Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Unknown logins - Possible malware. [Closed]


  • This topic is locked This topic is locked

#1
Wolfman360

Wolfman360

    Member

  • Member
  • PipPip
  • 32 posts

Good afternoon,

 

Unfortunately I've had several emails recently telling me someone has tried to access my Steam and Google account from America (I live in the UK). I've changed these passwords from another PC and have ran some scans to check. TDSSKiller crashed when I attempted to run it.

 

aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2016-06-21 14:29:00
-----------------------------
14:29:00.546    OS Version: Windows x64 6.2.9200 
14:29:00.547    Number of processors: 4 586 0x4501
14:29:00.550    ComputerName: BISMILLAH  UserName: Daniel
14:29:07.792    Initialize success
14:29:07.856    VM: initialized successfully
14:29:07.859    VM: Intel CPU supported virtualized 
14:33:56.993    VM: disk I/O storahci.sys
14:34:01.383    AVAST engine defs: 16062100
14:34:06.494    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000030
14:34:06.502    Disk 0 Vendor: WDC_WD10JPVX-22JC3T0 01.01A01 Size: 953869MB BusType: 11
14:34:06.835    Disk 0 MBR read successfully
14:34:06.845    Disk 0 MBR scan
14:34:06.966    Disk 0 unknown MBR code
14:34:06.975    Disk 0 Partition 1 00     EE            GPT           2097151 MB offset 1
14:34:07.291    Disk 0 scanning C:\WINDOWS\system32\drivers
14:35:02.241    Service scanning
14:37:05.400    Modules scanning
14:37:05.442    Disk 0 trace - called modules:
14:37:05.459    
14:37:05.487    Disk 0 statistics 136809/0/0 @ 2.69 MB/s
14:37:05.509    Scan finished successfully
14:37:47.013    Disk 0 MBR has been saved successfully to "C:\Users\Daniel\Downloads\MBR.dat"
14:37:47.032    The log file has been saved successfully to "C:\Users\Daniel\Downloads\aswMBR.txt"
 
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-06-2016 01
Ran by Daniel (administrator) on BISMILLAH (21-06-2016 14:43:17)
Running from C:\Users\Daniel\Downloads
Loaded Profiles: Daniel &  (Available Profiles: Daniel)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
() C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Visicom Media Inc.) C:\ProgramData\ManyCam\Service\service.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe
(VMware) C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Spotify Ltd) C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Visicom Media Inc.) C:\Program Files (x86)\ManyCam\ManyCam.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
() C:\Program Files (x86)\Dynatrace\LastMile\bin\GomezPEER.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Sun Microsystems, Inc.) C:\Program Files (x86)\Dynatrace\LastMile\jre\bin\java.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QuickAccess.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\nacl64.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\Daniel\Downloads\aswmbr (1).exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Skype Technologies S.A.) C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\SkypeShell.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files (x86)\Acer\Live Updater\updater.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Daniel\Downloads\FRST64 (1).exe
(Kaspersky Lab ZAO) C:\Users\Daniel\Downloads\tdsskiller.exe
(Kaspersky Lab ZAO) C:\Users\Daniel\AppData\Local\Temp\{5E7DC75E-06B9-4EC0-8BA4-36872FF9C8C4}\{BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [VMware Netlink 3 HV Install Utility] => C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnliu.exe [70328 2014-11-20] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-05-05] (Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [62208 2014-10-17] (Acer Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7405752 2016-06-15] (AVAST Software)
HKLM-x32\...\Run: [Adobe Creative Cloud] => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [AcerPortal] => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2621696 2014-10-20] (Acer)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-27] (Electronic Arts)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [289328 2016-05-29] ()
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [Spotify Web Helper] => C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-01-25] (Spotify Ltd)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [GoogleChromeAutoLaunch_9CB2B8404301F8169D10E27C4B481A41] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [941720 2016-06-15] (Google Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [61200 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [103696 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [10116392 2015-12-21] (Visicom Media Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53130368 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\RunOnce: [Uninstall C:\Users\Daniel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Daniel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64"
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AcerPortal] => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2621696 2014-10-20] (Acer)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3619160 2015-01-27] (Electronic Arts)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe [289328 2016-05-29] ()
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Spotify Web Helper] => C:\Users\Daniel\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-01-25] (Spotify Ltd)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleChromeAutoLaunch_9CB2B8404301F8169D10E27C4B481A41] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [941720 2016-06-15] (Google Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [61200 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [103696 2015-11-30] (Apple Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [10116392 2015-12-21] (Visicom Media Inc.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53130368 2016-05-17] (Skype Technologies S.A.)
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [Uninstall C:\Users\Daniel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Daniel\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64"
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-06-15] (AVAST Software)
ShellIconOverlayIdentifiers: [ACloudSyncedRF] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-10-20] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncedSF] -> {5D5F18B7-D59B-4B18-A3E9-0A4BDCCCB699} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-10-20] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-10-20] (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll [2014-10-20] (Acer Incorporated)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Last Mile.lnk [2016-06-15]
ShortcutTarget: Last Mile.lnk -> C:\Program Files (x86)\Dynatrace\LastMile\bin\GomezPEER.exe ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100
Tcpip\..\Interfaces\{dd117b47-954f-4e21-aaf8-5a365658d137}: [DhcpNameServer] 194.168.4.100 194.168.8.100
 
Internet Explorer:
==================
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com/?pc=ACJB
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://uk.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-214036272-3329120688-3169881572-1001 -> DefaultScope {EAD469F4-AA29-11E4-8274-F8A9639CDE48} URL = 
SearchScopes: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {EAD469F4-AA29-11E4-8274-F8A9639CDE48} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-05-17] (Microsoft Corporation)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-05-17] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-03-01] (Oracle Corporation)
BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-05-17] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-03-01] (Oracle Corporation)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
 
FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\8x5xtguz.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-13] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-13] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1214154.dll [2014-11-26] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-10] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-03-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-03-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-10-21] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-12] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-12] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-07-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-04-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-214036272-3329120688-3169881572-1001: @nsroblox.roblox.com/launcher -> C:\Users\Daniel\AppData\Local\Roblox\Versions\version-4993687f79834cd9\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-214036272-3329120688-3169881572-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\Daniel\AppData\Local\Roblox\Versions\version-4993687f79834cd9\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-214036272-3329120688-3169881572-1001: SkypePlugin -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\npGatewayNpapi.dll [2016-03-21] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-214036272-3329120688-3169881572-1001: SkypePlugin64 -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\npGatewayNpapi-x64.dll [2016-03-21] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @nsroblox.roblox.com/launcher -> C:\Users\Daniel\AppData\Local\Roblox\Versions\version-4993687f79834cd9\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @nsroblox.roblox.com/launcher64 -> C:\Users\Daniel\AppData\Local\Roblox\Versions\version-4993687f79834cd9\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: SkypePlugin -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\npGatewayNpapi.dll [2016-03-21] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: SkypePlugin64 -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\npGatewayNpapi-x64.dll [2016-03-21] (Skype Technologies S.A.)
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-06-15]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor => not found
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-06-15]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://homepage-web.com/?s=acer&m=home
CHR StartupUrls: Default -> "hxxp://homepage-web.com/?s=acer&m=start"
CHR Profile: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-04]
CHR Extension: (Google Docs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-24]
CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Google Search) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (Google Play Music) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2016-06-10]
CHR Extension: (Google Sheets) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-04]
CHR Extension: (iCloud Bookmarks) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2015-12-25]
CHR Extension: (Google Docs Offline) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Avast Online Security) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-15]
CHR Extension: (Qmee) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbaanpgkpkoamihninlcegnjclcpibde [2016-03-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Recently Closed Tabs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\opefiliglgllmponlmoajkfbcaigocfc [2016-02-22]
CHR Extension: (Gmail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Skype Calling) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\poghlonenmjdkfghdpfomojhhfggildk [2016-03-31]
CHR Profile: C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Docs) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-09]
CHR Extension: (Google Drive) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-09]
CHR Extension: (YouTube) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-09]
CHR Extension: (Google Search) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-09]
CHR Extension: (Gmail) - C:\Users\Daniel\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-09]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2016-06-15]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-06-15]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2021592 2016-04-05] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-06-15] (AVAST Software)
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2014-11-14] (BitRaider, LLC)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [3096832 2014-10-17] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3009776 2016-05-27] (Microsoft Corporation)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573544 2014-03-21] (Acer Incorporated)
R2 ftnlsv3hv; C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe [225976 2014-11-20] ()
R2 ftscanmgr; C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe [3649720 2014-11-20] ()
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed]
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [370064 2015-11-19] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [459496 2014-03-17] (Acer Incorporate)
R2 ManyCam Service; C:\ProgramData\ManyCam\Service\service.exe [77528 2015-12-15] (Visicom Media Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910640 2015-03-01] (Electronic Arts)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1289968 2016-05-29] (Overwolf LTD)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457960 2014-03-21] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-03-21] (Acer Incorporate)
R2 vmware-view-usbd; C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe [1979608 2014-11-18] (VMware, Inc.)
R2 vmwsprrdpwks; C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe [228024 2014-11-21] (VMware)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 wsnm; C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe [528600 2014-12-01] (VMware, Inc.)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-06-15] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-06-15] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-06-15] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-06-15] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-06-15] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-06-15] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-06-15] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-06-15] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287528 2016-06-15] (AVAST Software)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2014-11-20] (BitRaider)
R3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [165376 2015-10-30] (Microsoft Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv.sys [49272 2014-12-29] (Visicom Media Inc.)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-06-21] (Malwarebytes)
R3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (Visicom Media Inc.)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek                                            )
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [761600 2015-06-24] (Realsil Semiconductor Corporation)
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 aswMBR; C:\Users\Daniel\AppData\Local\Temp\aswMBR.sys [62728 2016-06-21] () [File not signed]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-06-21 14:42 - 2016-06-21 14:45 - 00275618 _____ C:\TDSSKiller.3.1.0.9_21.06.2016_14.42.37_log.txt
2016-06-21 14:42 - 2016-06-21 14:42 - 00246848 ____N (Kaspersky Lab, Yury Parshin) C:\WINDOWS\system32\Drivers\59382956.sys
2016-06-21 14:41 - 2016-06-21 14:42 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\Daniel\Downloads\tdsskiller.exe
2016-06-21 14:41 - 2016-06-21 14:41 - 02387456 _____ (Farbar) C:\Users\Daniel\Downloads\FRST64 (1).exe
2016-06-21 14:37 - 2016-06-21 14:37 - 00001376 _____ C:\Users\Daniel\Downloads\aswMBR.txt
2016-06-21 14:37 - 2016-06-21 14:37 - 00000512 _____ C:\Users\Daniel\Downloads\MBR.dat
2016-06-21 14:28 - 2016-06-21 14:28 - 22851472 _____ (Malwarebytes ) C:\Users\Daniel\Downloads\mbam-setup-2.2.1.1043 (1).exe
2016-06-21 14:28 - 2016-06-21 14:28 - 05200384 _____ (AVAST Software) C:\Users\Daniel\Downloads\aswmbr (1).exe
2016-06-21 00:16 - 2016-06-21 00:16 - 00301864 _____ C:\Users\Daniel\Downloads\South-East-Region-Centenary-Event-Booking-Form.pdf
2016-06-17 20:05 - 2016-06-17 20:09 - 01663328 _____ C:\Users\Daniel\Downloads\Heart Failure Presentation (2).pptx
2016-06-16 18:17 - 2016-05-28 07:13 - 01401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-06-16 18:17 - 2016-05-28 07:13 - 00046784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-06-16 18:17 - 2016-05-28 05:35 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdlrecover.exe
2016-06-16 18:17 - 2016-05-28 05:29 - 22379008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-06-16 18:17 - 2016-05-28 05:19 - 24605696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-06-16 18:17 - 2016-05-28 05:18 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-06-16 18:17 - 2016-05-28 05:18 - 07977472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-06-16 18:17 - 2016-05-28 05:17 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-06-16 18:17 - 2016-05-28 05:16 - 19344384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-06-16 18:17 - 2016-05-28 05:14 - 18674176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-06-16 18:17 - 2016-05-28 05:08 - 13385728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-06-16 18:17 - 2016-05-28 05:08 - 06295552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-06-16 18:17 - 2016-05-28 05:06 - 12128256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-06-16 18:17 - 2016-05-28 05:06 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-06-16 18:17 - 2016-05-28 05:05 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-06-16 18:17 - 2016-05-28 05:04 - 06973952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-06-16 18:17 - 2016-05-28 05:03 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-06-16 18:17 - 2016-05-28 05:03 - 02609664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-06-16 18:17 - 2016-05-28 05:00 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-06-16 18:17 - 2016-05-28 05:00 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-06-16 18:17 - 2016-05-28 05:00 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-06-16 18:17 - 2016-05-28 05:00 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-06-16 18:17 - 2016-05-28 04:58 - 07832576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-06-16 18:17 - 2016-05-28 04:58 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-06-16 18:16 - 2016-05-28 07:13 - 00290496 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-06-16 18:16 - 2016-05-28 07:13 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-06-16 18:16 - 2016-05-28 06:25 - 04268880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
2016-06-16 18:16 - 2016-05-28 06:23 - 00388384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2016-06-16 18:16 - 2016-05-28 06:22 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-06-16 18:16 - 2016-05-28 06:22 - 04387680 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
2016-06-16 18:16 - 2016-05-28 06:20 - 00430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2016-06-16 18:16 - 2016-05-28 06:09 - 00501600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-06-16 18:16 - 2016-05-28 06:08 - 00693600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-06-16 18:16 - 2016-05-28 06:07 - 03675512 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-06-16 18:16 - 2016-05-28 06:07 - 02921880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-06-16 18:16 - 2016-05-28 06:07 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-06-16 18:16 - 2016-05-28 06:07 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-06-16 18:16 - 2016-05-28 06:07 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-06-16 18:16 - 2016-05-28 06:07 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-06-16 18:16 - 2016-05-28 06:07 - 00331616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-06-16 18:16 - 2016-05-28 06:06 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-06-16 18:16 - 2016-05-28 06:06 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-06-16 18:16 - 2016-05-28 06:06 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-06-16 18:16 - 2016-05-28 06:06 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-06-16 18:16 - 2016-05-28 06:06 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-06-16 18:16 - 2016-05-28 06:05 - 04515264 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-06-16 18:16 - 2016-05-28 06:04 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-06-16 18:16 - 2016-05-28 06:04 - 00431296 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2016-06-16 18:16 - 2016-05-28 06:04 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-06-16 18:16 - 2016-05-28 05:58 - 01996640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-06-16 18:16 - 2016-05-28 05:58 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-06-16 18:16 - 2016-05-28 05:57 - 02548944 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2016-06-16 18:16 - 2016-05-28 05:57 - 02195632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2016-06-16 18:16 - 2016-05-28 05:57 - 01594416 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-06-16 18:16 - 2016-05-28 05:57 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-06-16 18:16 - 2016-05-28 05:57 - 00649792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-06-16 18:16 - 2016-05-28 05:57 - 00636304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-06-16 18:16 - 2016-05-28 05:57 - 00546456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-06-16 18:16 - 2016-05-28 05:57 - 00521664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-06-16 18:16 - 2016-05-28 05:57 - 00316256 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-06-16 18:16 - 2016-05-28 05:35 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsdport.sys
2016-06-16 18:16 - 2016-05-28 05:31 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdlrecover.exe
2016-06-16 18:16 - 2016-05-28 05:31 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-06-16 18:16 - 2016-05-28 05:27 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-06-16 18:16 - 2016-05-28 05:26 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2016-06-16 18:16 - 2016-05-28 05:26 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-06-16 18:16 - 2016-05-28 05:24 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-06-16 18:16 - 2016-05-28 05:22 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-06-16 18:16 - 2016-05-28 05:22 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2016-06-16 18:16 - 2016-05-28 05:22 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-06-16 18:16 - 2016-05-28 05:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2016-06-16 18:16 - 2016-05-28 05:22 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-06-16 18:16 - 2016-05-28 05:21 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrokerLib.dll
2016-06-16 18:16 - 2016-05-28 05:21 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-06-16 18:16 - 2016-05-28 05:20 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-06-16 18:16 - 2016-05-28 05:19 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2016-06-16 18:16 - 2016-05-28 05:18 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2016-06-16 18:16 - 2016-05-28 05:18 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-06-16 18:16 - 2016-05-28 05:18 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2016-06-16 18:16 - 2016-05-28 05:18 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-06-16 18:16 - 2016-05-28 05:17 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-06-16 18:16 - 2016-05-28 05:17 - 00963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2016-06-16 18:16 - 2016-05-28 05:17 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-06-16 18:16 - 2016-05-28 05:16 - 00690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2016-06-16 18:16 - 2016-05-28 05:16 - 00684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
2016-06-16 18:16 - 2016-05-28 05:16 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2016-06-16 18:16 - 2016-05-28 05:16 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-06-16 18:16 - 2016-05-28 05:16 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2016-06-16 18:16 - 2016-05-28 05:15 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-06-16 18:16 - 2016-05-28 05:15 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-06-16 18:16 - 2016-05-28 05:15 - 00794624 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-06-16 18:16 - 2016-05-28 05:15 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-06-16 18:16 - 2016-05-28 05:14 - 01716736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-06-16 18:16 - 2016-05-28 05:14 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-06-16 18:16 - 2016-05-28 05:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-06-16 18:16 - 2016-05-28 05:14 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-06-16 18:16 - 2016-05-28 05:14 - 00606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-06-16 18:16 - 2016-05-28 05:14 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-06-16 18:16 - 2016-05-28 05:13 - 00990208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-06-16 18:16 - 2016-05-28 05:13 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-06-16 18:16 - 2016-05-28 05:13 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-06-16 18:16 - 2016-05-28 05:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-06-16 18:16 - 2016-05-28 05:13 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2016-06-16 18:16 - 2016-05-28 05:12 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-06-16 18:16 - 2016-05-28 05:12 - 00614400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-06-16 18:16 - 2016-05-28 05:12 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
2016-06-16 18:16 - 2016-05-28 05:11 - 01445888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-06-16 18:16 - 2016-05-28 05:11 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-06-16 18:16 - 2016-05-28 05:11 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-06-16 18:16 - 2016-05-28 05:11 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-06-16 18:16 - 2016-05-28 05:11 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-06-16 18:16 - 2016-05-28 05:09 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-06-16 18:16 - 2016-05-28 05:06 - 01339904 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2016-06-16 18:16 - 2016-05-28 05:05 - 03664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-06-16 18:16 - 2016-05-28 05:05 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-06-16 18:16 - 2016-05-28 05:05 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-06-16 18:16 - 2016-05-28 05:03 - 05323776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-06-16 18:16 - 2016-05-28 05:03 - 01185280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationFramework.dll
2016-06-16 18:16 - 2016-05-28 05:02 - 03590144 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-06-16 18:16 - 2016-05-28 05:02 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-06-16 18:16 - 2016-05-28 05:02 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2016-06-16 18:16 - 2016-05-28 05:01 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-06-16 18:16 - 2016-05-28 05:01 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2016-06-16 18:16 - 2016-05-28 05:01 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-06-16 18:16 - 2016-05-28 05:00 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-06-16 18:16 - 2016-05-28 05:00 - 01730560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-06-16 18:16 - 2016-05-28 05:00 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2016-06-16 18:16 - 2016-05-28 04:58 - 04896256 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-06-16 18:16 - 2016-05-28 04:58 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-06-16 18:16 - 2016-05-28 04:58 - 02066432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-06-16 18:16 - 2016-05-28 04:57 - 02281472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-06-16 18:16 - 2016-05-28 04:55 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-06-16 18:15 - 2016-05-28 07:13 - 01184960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-06-16 18:15 - 2016-05-28 07:13 - 00514752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-06-16 18:15 - 2016-05-28 06:23 - 00312160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
2016-06-16 18:15 - 2016-05-28 06:22 - 00428896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2016-06-16 18:15 - 2016-05-28 06:22 - 00211296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2016-06-16 18:15 - 2016-05-28 06:22 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2016-06-16 18:15 - 2016-05-28 06:18 - 00357216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
2016-06-16 18:15 - 2016-05-28 06:16 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-06-16 18:15 - 2016-05-28 06:09 - 00170848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.exe
2016-06-16 18:15 - 2016-05-28 06:09 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-06-16 18:15 - 2016-05-28 06:08 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-06-16 18:15 - 2016-05-28 06:08 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-06-16 18:15 - 2016-05-28 06:04 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2016-06-16 18:15 - 2016-05-28 06:04 - 00111064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
2016-06-16 18:15 - 2016-05-28 06:04 - 00097096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
2016-06-16 18:15 - 2016-05-28 06:03 - 00131248 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
2016-06-16 18:15 - 2016-05-28 05:57 - 00577376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-06-16 18:15 - 2016-05-28 05:35 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-06-16 18:15 - 2016-05-28 05:31 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-06-16 18:15 - 2016-05-28 05:29 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
2016-06-16 18:15 - 2016-05-28 05:29 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-06-16 18:15 - 2016-05-28 05:29 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxp.dll
2016-06-16 18:15 - 2016-05-28 05:28 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-06-16 18:15 - 2016-05-28 05:28 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-06-16 18:15 - 2016-05-28 05:28 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll
2016-06-16 18:15 - 2016-05-28 05:27 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-06-16 18:15 - 2016-05-28 05:26 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-06-16 18:15 - 2016-05-28 05:26 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2016-06-16 18:15 - 2016-05-28 05:26 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-06-16 18:15 - 2016-05-28 05:25 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2016-06-16 18:15 - 2016-05-28 05:25 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-06-16 18:15 - 2016-05-28 05:24 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-06-16 18:15 - 2016-05-28 05:24 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ndu.sys
2016-06-16 18:15 - 2016-05-28 05:24 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-06-16 18:15 - 2016-05-28 05:24 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-06-16 18:15 - 2016-05-28 05:24 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-06-16 18:15 - 2016-05-28 05:24 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2016-06-16 18:15 - 2016-05-28 05:24 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FwRemoteSvr.dll
2016-06-16 18:15 - 2016-05-28 05:23 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-06-16 18:15 - 2016-05-28 05:23 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2016-06-16 18:15 - 2016-05-28 05:22 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-06-16 18:15 - 2016-05-28 05:22 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-06-16 18:15 - 2016-05-28 05:22 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-06-16 18:15 - 2016-05-28 05:22 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptsvc.dll
2016-06-16 18:15 - 2016-05-28 05:21 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-06-16 18:15 - 2016-05-28 05:21 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-06-16 18:15 - 2016-05-28 05:20 - 00511488 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
2016-06-16 18:15 - 2016-05-28 05:20 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\polstore.dll
2016-06-16 18:15 - 2016-05-28 05:20 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2016-06-16 18:15 - 2016-05-28 05:20 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GnssAdapter.dll
2016-06-16 18:15 - 2016-05-28 05:20 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2016-06-16 18:15 - 2016-05-28 05:20 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2016-06-16 18:15 - 2016-05-28 05:19 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-06-16 18:15 - 2016-05-28 05:19 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-06-16 18:15 - 2016-05-28 05:19 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2016-06-16 18:15 - 2016-05-28 05:19 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2016-06-16 18:15 - 2016-05-28 05:18 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-06-16 18:15 - 2016-05-28 05:18 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPSECSVC.DLL
2016-06-16 18:15 - 2016-05-28 05:17 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
2016-06-16 18:15 - 2016-05-28 05:17 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-06-16 18:15 - 2016-05-28 05:17 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-06-16 18:15 - 2016-05-28 05:17 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2016-06-16 18:15 - 2016-05-28 05:16 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\polstore.dll
2016-06-16 18:15 - 2016-05-28 05:16 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2016-06-16 18:15 - 2016-05-28 05:15 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-06-16 18:15 - 2016-05-28 05:15 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2016-06-16 18:15 - 2016-05-28 05:15 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2016-06-16 18:15 - 2016-05-28 05:14 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-06-16 18:15 - 2016-05-28 05:14 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2016-06-16 18:15 - 2016-05-28 05:13 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-06-16 18:15 - 2016-05-28 05:13 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-06-16 18:15 - 2016-05-28 05:13 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-06-16 18:15 - 2016-05-28 05:11 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-06-16 18:15 - 2016-05-28 05:11 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-06-16 18:15 - 2016-05-28 05:11 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
2016-06-16 18:15 - 2016-05-28 05:04 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-06-16 18:15 - 2016-05-28 05:04 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-06-16 18:15 - 2016-05-28 05:03 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2016-06-16 18:15 - 2016-05-28 05:03 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-06-16 18:15 - 2016-05-28 05:02 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2016-06-16 18:15 - 2016-05-28 05:01 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-06-16 18:15 - 2016-05-28 05:00 - 02230272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-06-16 18:15 - 2016-05-28 05:00 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-06-16 18:15 - 2016-05-28 05:00 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-06-16 18:15 - 2016-05-28 04:59 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-06-16 18:15 - 2016-05-28 04:53 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2016-06-16 16:51 - 2016-06-16 17:04 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Bitcoin
2016-06-16 16:50 - 2016-06-16 16:50 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bitcoin Core
2016-06-16 16:50 - 2016-06-16 16:50 - 00000000 ____D C:\Program Files\Bitcoin
2016-06-16 16:49 - 2016-06-16 16:49 - 13613832 _____ (Bitcoin Core project) C:\Users\Daniel\Downloads\bitcoin-0.12.1-win64-setup.exe
2016-06-16 16:17 - 2016-06-16 16:19 - 72223460 _____ C:\Users\Daniel\Downloads\Ethereum-win64-latest (2).exe
2016-06-16 16:13 - 2016-06-16 16:16 - 55214080 _____ C:\Users\Daniel\Downloads\Ethereum-win64-latest (1).exe
2016-06-15 23:50 - 2016-06-16 00:18 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Litecoin
2016-06-15 23:49 - 2016-06-15 23:49 - 12430947 _____ (Litecoin Core project) C:\Users\Daniel\Downloads\litecoin-0.10.4.0-win64-setup.exe
2016-06-15 23:49 - 2016-06-15 23:49 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Litecoin Core
2016-06-15 23:49 - 2016-06-15 23:49 - 00000000 ____D C:\Program Files\Litecoin
2016-06-15 23:40 - 2016-06-15 23:40 - 06657336 _____ C:\Users\Daniel\Downloads\m-cpuminer-qt-64-win.zip
2016-06-15 23:40 - 2015-10-16 00:37 - 00000000 ____D C:\Users\Daniel\Documents\m-cpuminer-qt-64-win
2016-06-15 23:33 - 2016-06-15 23:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Gomez
2016-06-15 23:33 - 2016-06-15 23:33 - 00000000 ____D C:\Users\Daniel\AppData\Local\Gomez
2016-06-15 23:27 - 2016-06-15 23:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dynatrace Peer
2016-06-15 23:27 - 2016-06-15 23:27 - 00000000 ____D C:\Program Files (x86)\Dynatrace
2016-06-15 23:25 - 2016-06-15 23:26 - 138952768 _____ (Dynatrace) C:\Users\Daniel\Downloads\PEERInstall.exe
2016-06-15 23:05 - 2016-06-15 23:05 - 00094716 _____ C:\Users\Daniel\Downloads\so13fe_1_811794.pdf
2016-06-15 15:48 - 2016-06-15 15:48 - 00398152 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2016-06-15 15:47 - 2016-06-15 15:47 - 00052184 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2016-06-07 21:53 - 2013-03-24 05:00 - 00391168 _____ (CANON INC.) C:\WINDOWS\system32\CNMLMBW.DLL
2016-06-07 21:52 - 2013-02-04 15:12 - 00367104 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BWL.dll
2016-06-07 21:52 - 2012-11-09 10:41 - 00088064 _____ C:\WINDOWS\system32\CNC176CD.TBL
2016-06-07 21:52 - 2012-11-08 13:04 - 00282624 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BWC.dll
2016-06-07 21:52 - 2012-11-08 13:03 - 00106496 _____ (CANON INC.) C:\WINDOWS\system32\CNC_BWI.dll
2016-06-07 21:52 - 2008-08-25 18:02 - 00017920 _____ (CANON INC.) C:\WINDOWS\system32\CNHMCA6.dll
2016-06-06 23:04 - 2016-06-06 23:04 - 00185344 _____ C:\Users\Daniel\Downloads\Lippits Change Theory.ppt
2016-06-03 22:28 - 2016-06-03 22:28 - 00613597 _____ C:\Users\Daniel\Downloads\Bachelor_Nursing.pdf
2016-06-03 22:14 - 2016-06-03 22:14 - 00675535 _____ C:\Users\Daniel\Downloads\SN06779.pdf
2016-05-30 19:02 - 2016-05-30 19:02 - 01673788 _____ C:\Users\Daniel\Downloads\16936 - NHS Student Induction Booklet - v5.pdf
2016-05-29 22:55 - 2016-05-29 22:55 - 00204438 _____ C:\Users\Daniel\Downloads\188-DIVB564_Staff_Nurse_Clinical_Doctoral_Fellow_Project_Summary_-_D10 (5).pdf
2016-05-29 17:08 - 2016-05-29 17:08 - 00204438 _____ C:\Users\Daniel\Downloads\188-DIVB564_Staff_Nurse_Clinical_Doctoral_Fellow_Project_Summary_-_D10 (4).pdf
2016-05-29 16:53 - 2016-05-29 16:53 - 00204438 _____ C:\Users\Daniel\Downloads\188-DIVB564_Staff_Nurse_Clinical_Doctoral_Fellow_Project_Summary_-_D10 (3).pdf
2016-05-27 15:09 - 2016-05-27 15:09 - 00204438 _____ C:\Users\Daniel\Downloads\188-DIVB564_Staff_Nurse_Clinical_Doctoral_Fellow_Project_Summary_-_D10 (2).pdf
2016-05-27 13:42 - 2016-05-27 13:42 - 00020184 _____ C:\Users\Daniel\Downloads\Browning Daniel (31).pdf
2016-05-27 13:15 - 2016-05-27 13:15 - 03043044 _____ C:\Users\Daniel\Downloads\nhs_change_model_july2013 (1).pdf
2016-05-27 12:42 - 2016-05-27 12:42 - 03043044 _____ C:\Users\Daniel\Downloads\nhs_change_model_july2013.pdf
2016-05-26 16:55 - 2016-05-26 16:55 - 00717211 _____ C:\Users\Daniel\Downloads\ncor-audit-handbook-ozone (1).pdf
2016-05-26 15:29 - 2016-05-26 15:29 - 00717211 _____ C:\Users\Daniel\Downloads\ncor-audit-handbook-ozone.pdf
2016-05-25 11:21 - 2016-05-25 11:21 - 00155311 _____ C:\Users\Daniel\Downloads\ContentServer (2).pdf
2016-05-25 11:18 - 2016-05-25 11:18 - 01112070 _____ C:\Users\Daniel\Downloads\99400818.pdf
2016-05-25 11:10 - 2016-05-25 11:10 - 00838919 _____ C:\Users\Daniel\Downloads\2.pdf
2016-05-24 18:11 - 2016-05-24 18:11 - 00204438 _____ C:\Users\Daniel\Downloads\188-DIVB564_Staff_Nurse_Clinical_Doctoral_Fellow_Project_Summary_-_D10 (1).pdf
2016-05-24 18:04 - 2016-05-24 18:04 - 00227856 _____ C:\Users\Daniel\Downloads\188-DIVB564-JD-PS (2).pdf
2016-05-23 12:02 - 2016-05-23 12:02 - 00055077 _____ C:\Users\Daniel\Downloads\StudentCoversheet-94119-20130319235319987 (3).pdf
2016-05-23 11:45 - 2016-05-23 11:45 - 01385054 _____ C:\Users\Daniel\Downloads\D. Browning claim.pdf
2016-05-22 16:14 - 2016-05-22 16:14 - 00422031 _____ C:\Users\Daniel\Documents\Journal of Infection Prevention-2015-Seale-167-73.pdf
2016-05-22 11:51 - 2016-05-22 11:51 - 00162031 _____ C:\Users\Daniel\Downloads\ejbrm-volume7-issue1-article198.pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-06-21 14:45 - 2015-08-31 18:31 - 00032445 _____ C:\Users\Daniel\Downloads\FRST.txt
2016-06-21 14:43 - 2015-08-31 18:31 - 00000000 ____D C:\FRST
2016-06-21 14:37 - 2014-10-10 22:38 - 00000000 ___RD C:\Users\Daniel\Documents\Healthcare
2016-06-21 14:34 - 2015-03-08 00:39 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-06-21 14:32 - 2014-11-24 22:42 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype
2016-06-21 14:31 - 2016-01-26 00:35 - 00004156 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{38C2185D-C843-42D6-B0DE-8DF4746F92B4}
2016-06-21 14:30 - 2016-04-15 15:06 - 00001175 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-06-21 14:30 - 2015-03-08 00:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-06-21 14:30 - 2015-03-08 00:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-06-21 14:28 - 2015-01-07 02:00 - 00000000 ____D C:\ProgramData\Origin
2016-06-21 14:27 - 2014-09-23 18:20 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-06-21 14:26 - 2015-09-28 01:01 - 00000000 ___RD C:\Users\Daniel\iCloudDrive
2016-06-21 14:24 - 2015-12-15 20:36 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-06-21 14:24 - 2014-09-23 18:15 - 00000000 __SHD C:\Users\Daniel\IntelGraphicsProfiles
2016-06-21 00:39 - 2015-12-15 20:40 - 00000000 ____D C:\Users\Daniel
2016-06-21 00:31 - 2014-09-23 18:21 - 00002276 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-21 00:31 - 2014-09-23 18:21 - 00002264 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-06-21 00:31 - 2014-09-23 18:20 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-06-21 00:29 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-06-21 00:29 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-06-21 00:22 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-06-21 00:20 - 2014-10-02 22:16 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-06-21 00:06 - 2014-11-21 14:35 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe
2016-06-17 19:49 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-06-17 19:49 - 2015-03-29 15:07 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-06-17 19:39 - 2014-09-23 18:14 - 00000000 ____D C:\Users\Daniel\AppData\Local\Packages
2016-06-17 19:22 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2016-06-17 18:57 - 2014-09-24 01:03 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-06-17 18:54 - 2015-12-15 21:03 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-06-17 18:54 - 2015-12-15 20:31 - 00439736 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-06-16 23:30 - 2015-10-30 07:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-06-16 23:27 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-06-16 23:27 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2016-06-16 23:27 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-06-16 23:27 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-06-16 23:27 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-06-16 23:15 - 2016-01-22 20:57 - 00000000 ____D C:\Users\Daniel\AppData\Local\Battle.net
2016-06-16 22:13 - 2016-01-22 20:55 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-06-16 20:31 - 2014-09-23 18:24 - 00000000 ____D C:\Program Files (x86)\Steam
2016-06-16 20:09 - 2014-11-04 12:03 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2016-06-16 16:05 - 2016-03-17 19:40 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Mist
2016-06-16 15:52 - 2016-01-27 18:12 - 00004008 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1453914725
2016-06-16 15:52 - 2016-01-27 18:12 - 00001086 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-06-16 01:13 - 2014-09-29 19:50 - 142482544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-06-16 01:13 - 2014-09-29 19:50 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-06-15 15:48 - 2014-11-04 12:02 - 00465792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2016-06-15 15:48 - 2014-11-04 12:02 - 00287528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2016-06-15 15:48 - 2014-11-04 12:02 - 00166432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2016-06-15 15:48 - 2014-11-04 12:02 - 00107792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2016-06-15 15:48 - 2014-11-04 12:02 - 00103064 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2016-06-15 15:48 - 2014-11-04 12:02 - 00074544 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2016-06-15 15:48 - 2014-11-04 12:02 - 00037656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2016-06-15 15:47 - 2016-01-27 02:52 - 00037144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2016-06-15 15:47 - 2014-11-04 12:02 - 01070904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2016-06-15 15:34 - 2015-08-04 23:53 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-14 19:33 - 2015-10-30 08:26 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-06-14 19:33 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-06-13 11:42 - 2014-05-16 09:13 - 00000000 ____D C:\Program Files (x86)\Adobe
2016-06-13 11:35 - 2014-11-04 12:00 - 00000000 ____D C:\ProgramData\Package Cache
2016-06-11 14:58 - 2015-12-16 13:12 - 00000000 ___RD C:\Users\Daniel\Creative Cloud Files
2016-06-11 14:58 - 2014-10-06 23:29 - 00000000 ____D C:\ProgramData\boost_interprocess
2016-06-09 06:57 - 2015-01-10 00:56 - 00000000 ____D C:\Program Files (x86)\Overwolf
2016-06-08 16:26 - 2016-02-18 23:30 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\ManyCam
2016-06-05 21:19 - 2015-09-28 00:59 - 00003494 _____ C:\WINDOWS\System32\Tasks\Apple Diagnostics
2016-06-02 23:48 - 2016-01-22 21:01 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2016-06-02 22:26 - 2014-11-24 14:05 - 00000000 ____D C:\ProgramData\Skype
2016-06-02 22:25 - 2016-02-19 23:00 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-05-28 06:55 - 2015-12-15 20:35 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-05-24 00:23 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2016-05-22 12:44 - 2016-01-22 20:57 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Battle.net
 
==================== Files in the root of some directories =======
 
2015-12-15 20:36 - 2015-12-15 20:36 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-09-02 00:07 - 2015-09-02 00:07 - 0019535 _____ () C:\ProgramData\empty.ico
 
Some files in TEMP:
====================
C:\Users\Daniel\AppData\Local\Temp\D422.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-06-07 22:20
 
==================== End of FRST.txt ============================
 
 
 
 
 
 
 
 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-06-2016 01
Ran by Daniel (2016-06-21 14:50:23)
Running from C:\Users\Daniel\Downloads
Windows 10 Home Version 1511 (X64) (2015-12-15 20:15:46)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-214036272-3329120688-3169881572-500 - Administrator - Disabled)
Daniel (S-1-5-21-214036272-3329120688-3169881572-1001 - Administrator - Enabled) => C:\Users\Daniel
DefaultAccount (S-1-5-21-214036272-3329120688-3169881572-503 - Limited - Disabled)
Guest (S-1-5-21-214036272-3329120688-3169881572-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.04.3005 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.01.2002 - Acer Incorporated)
abMedia (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.05.2011.0 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.00.2013.0 - Acer Incorporated)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8105 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.02.2006 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8104 - Acer Incorporated)
Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3012 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8106 - Acer Incorporated)
Acer Remote Files (HKLM\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 1.02.2003 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2001.4 - Acer Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.7.0.272 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 22.0.0.192 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.1.1 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.04)  MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.04 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.16) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.16 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.4.154 - Adobe Systems, Inc.)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.02.2004.7 - Acer Incorporated)
Apple Application Support (32-bit) (HKLM-x32\...\{649A1FD9-5892-46AD-8DF0-C4A43FF61CB7}) (Version: 4.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{0DE0A178-AC7B-4650-806C-CF226DE03766}) (Version: 4.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Avast Pro Antivirus (HKLM-x32\...\Avast) (Version: 11.2.2262 - AVAST Software)
Banished (HKLM-x32\...\Steam App 242920) (Version:  - Shining Rock Software LLC)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
BattleSpace (HKLM-x32\...\Steam App 306930) (Version:  - Funnel Inc.)
BBC iPlayer Downloads (HKLM-x32\...\{26FB1064-0CC3-49D8-97AB-CAE376428297}) (Version: 1.10.0 - BBC)
Besiege (HKLM-x32\...\Steam App 346010) (Version:  - Spiderling Studios)
Bitcoin Core (64-bit) (HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Bitcoin Core (64-bit)) (Version: 0.12.1 - Bitcoin Core project)
Bitcoin Core (64-bit) (HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Bitcoin Core (64-bit)) (Version: 0.12.1 - Bitcoin Core project)
BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Cheat Engine 6.5 (HKLM-x32\...\Cheat Engine 6.5_is1) (Version:  - Cheat Engine)
Cities: Skylines (HKLM-x32\...\Steam App 255710) (Version:  - Colossal Order Ltd.)
CorsixTH 0.40 (HKLM-x32\...\CorsixTH) (Version: 0.40 - CorsixTH Team)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Crash Time II (HKLM-x32\...\Steam App 11390) (Version:  - RTL interactive)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.3721 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.4314.55 - CyberLink Corp.)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Dream (HKLM-x32\...\Steam App 229580) (Version:  - HyperSloth)
Dropbox (HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Dropbox (HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Dynatrace Peer (HKLM-x32\...\GomezPEER) (Version: 3.2 - Dynatrace)
eBay Worldwide (HKLM-x32\...\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
Ethereum (HKLM-x32\...\Ethereum 0.9.41 (Win64)) (Version: 0.9.41 - ethereum.org)
Frozen Cortex (HKLM-x32\...\Steam App 237350) (Version:  - Mode 7)
FTL: Faster Than Light (HKLM-x32\...\Steam App 212680) (Version:  - Subset Games)
Game Dev Tycoon (HKLM-x32\...\Steam App 239820) (Version:  - Greenheart Games)
Gameforge Live 2.0.5 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.5 - Gameforge)
GameRanger (HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\GameRanger) (Version:  - GameRanger Technologies)
GameRanger (HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\GameRanger) (Version:  - GameRanger Technologies)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 51.0.2704.103 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
HOARD (HKLM-x32\...\Steam App 63000) (Version:  - Big Sandwich Games)
I am Bread (HKLM-x32\...\Steam App 327890) (Version:  - Bossa Studios)
iCloud (HKLM\...\{4B48E22A-2FB0-4EFA-B99E-954B1E50CD69}) (Version: 5.1.0.34 - Apple Inc.)
Identity Card (HKLM-x32\...\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.8101 - Acer Incorporated)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.23.1766 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4248 - Intel Corporation)
Intel® Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 1.1.165.1 - Intel Corporation)
Interplanetary (HKLM-x32\...\Steam App 278910) (Version:  - Team Jolly Roger)
iTunes (HKLM\...\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Java SE Development Kit 8 Update 25 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180250}) (Version: 8.0.250.18 - Oracle Corporation)
Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version:  - Squad)
King Arthur's Gold (HKLM-x32\...\Steam App 219830) (Version:  - )
Knights and Merchants (HKLM-x32\...\Steam App 253900) (Version:  - Topware Interactive)
Litecoin Core (64-bit) (HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Litecoin Core (64-bit)) (Version: 0.10.4.0 - Litecoin Core project)
Litecoin Core (64-bit) (HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Litecoin Core (64-bit)) (Version: 0.10.4.0 - Litecoin Core project)
Live Updater (HKLM-x32\...\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.8100 - Acer Incorporated)
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
ManyCam 5.1.0 (HKLM-x32\...\ManyCam) (Version: 5.1.0 - Visicom Media Inc.)
Medieval Engineers (HKLM-x32\...\Steam App 333950) (Version:  - Keen Software House)
Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 15.0.4833.1001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{02BAAFC5-4E16-42E6-A9F6-8DDE0B7ED3B8}) (Version: 1.0.0.0 - Mojang)
Mozilla Firefox 45.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 45.0.2 (x86 en-US)) (Version: 45.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.0.2 - Mozilla)
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\...\{551AC8F2-FEA2-4B45-ACF7-C98681233CC9}) (Version: 12.5.01200 - Nero AG)
NetBeans IDE 8.0.2 (HKLM\...\nbi-nb-base-8.0.2.0.201411181905) (Version: 8.0.2 - NetBeans.org)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4833.1001 - Microsoft Corporation) Hidden
One Finger Death Punch (HKLM-x32\...\Steam App 264200) (Version:  - Silver Dollar Games)
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Orcs Must Die! 2 (HKLM-x32\...\Steam App 201790) (Version:  - Robot Entertainment)
Orcs Must Die! Unchained (HKLM-x32\...\{8EBA33AF-48E0-4207-A4EE-96029415AD76}_is1) (Version:  - Gameforge 4D GmbH)
Origin (HKLM-x32\...\Origin) (Version: 9.5.3.636 - Electronic Arts, Inc.)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.95.40.0 - Overwolf Ltd.)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Planets Under Attack (HKLM-x32\...\Steam App 218510) (Version:  - Targem Games)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Playfire (HKLM-x32\...\{6b69b0a4-05aa-4ee8-a108-0ebb857ecba4}) (Version: 0.0.72.0 - Playfire)
Playfire (x32 Version: 0.0.72.0 - Playfire) Hidden
Pokki (HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Pokki) (Version: 0.269.7.768 - Pokki)
Pokki (HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Pokki) (Version: 0.269.7.768 - Pokki)
Pokki Start Menu (HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\Pokki_Start_Menu) (Version: 0.269.3.181 - )
Pokki Start Menu (HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Pokki_Start_Menu) (Version: 0.269.3.181 - )
Prerequisite installer (x32 Version: 12.0.0003 - Nero AG) Hidden
Prison Architect (HKLM-x32\...\Steam App 233450) (Version:  - Introversion Software)
Project Zomboid (HKLM-x32\...\Steam App 108600) (Version:  - The Indie Stone)
qBittorrent 3.3.3 (HKLM-x32\...\qBittorrent) (Version: 3.3.3 - The qBittorrent project)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.318 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.29 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21247 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.25.108.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
ROBLOX Player for Daniel (HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
ROBLOX Player for Daniel (HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
Rune Classic (HKLM-x32\...\Steam App 210950) (Version:  - Human Head Studios)
RuneScape Launcher 1.2.3 (HKLM-x32\...\{FAE99C85-0732-4C58-9C6B-10B5B12FA2E9}) (Version: 1.2.3 - Jagex Ltd)
SafeZone Stable 1.48.2066.101 (x32 Version: 1.48.2066.101 - Avast Software) Hidden
Scrap Mechanic (HKLM\...\Steam App 387990) (Version:  - Axolot Games)
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Sid Meier's Civilization: Beyond Earth (HKLM-x32\...\Steam App 65980) (Version:  - Firaxis Games)
Sid Meier's Railroads! (HKLM-x32\...\Steam App 7600) (Version:  - Firaxis Games)
SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Skype Web Plugin (HKLM-x32\...\{A51A9885-30AA-4736-BECA-5DB4BCB1A2EA}) (Version: 7.17.0.43 - Skype Technologies S.A.)
Skype™ 7.24 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.24.104 - Skype Technologies S.A.)
Space Engineers (HKLM-x32\...\Steam App 244850) (Version:  - Keen Software House)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Speedball 2 HD (HKLM-x32\...\Steam App 251690) (Version:  - Vivid Games)
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
Star Wars - Battlefront II (HKLM-x32\...\Steam App 6060) (Version:  - Pandemic Studios)
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
Star Wars: Empire at War Gold (HKLM-x32\...\Steam App 32470) (Version:  - Petroglyph)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
StarMade (HKLM-x32\...\Steam App 244770) (Version:  - Schine, GmbH)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Sumotori Full Version (HKLM-x32\...\Sumotori Full Version) (Version:  - )
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.32 - WildTangent) Hidden
The Escapists (HKLM-x32\...\Steam App 298630) (Version:  - Mouldy Toof Studios)
The Forest (HKLM-x32\...\Steam App 242760) (Version:  - Endnight Games Ltd)
The Jackbox Party Pack 2 (HKLM\...\Steam App 397460) (Version:  - Jackbox Games, Inc.)
The Ship (HKLM-x32\...\Steam App 2400) (Version:  - Outerlight Ltd.)
The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.7.65.1020 - Electronic Arts Inc.)
Theme Hospital (HKLM-x32\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.2 - Electronic Arts)
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
VMware Horizon Client (HKLM\...\{936DD031-2978-4374-842C-D18E92F9DFB5}) (Version: 3.2.0.24246 - VMware, Inc.)
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.10.20 - WildTangent) Hidden
WinRAR 5.21 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
X-Blades (HKLM-x32\...\Steam App 7510) (Version:  - Topware Interactive)
YTD Video Downloader 4.8.9 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.8.9 - GreenTree Applications SRL) <==== ATTENTION
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-170F5F5A3E94}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Daniel\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{8CE9991C-CC9B-42FA-85CF-BEFCB1F5DC30}\InprocServer32 -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\GatewayActiveX-x64.dll (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{AFD4369B-8A38-4407-882D-8297641DCFDF}\localserver32 -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\GatewayVersion-x64.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\EdgeCalling.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Daniel\AppData\Local\Roblox\Versions\version-4993687f79834cd9\RobloxProxy64.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-170F5F5A3E94}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Daniel\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{8CE9991C-CC9B-42FA-85CF-BEFCB1F5DC30}\InprocServer32 -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\GatewayActiveX-x64.dll (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{AFD4369B-8A38-4407-882D-8297641DCFDF}\localserver32 -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\GatewayVersion-x64.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Daniel\AppData\Local\SkypePlugin\7.17.0.43\EdgeCalling.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Daniel\AppData\Local\Roblox\Versions\version-4993687f79834cd9\RobloxProxy64.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {017C94E1-A077-418E-BA81-7EE616B4CF28} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {06D1AF14-B4E9-46FB-B6FA-6521A6FF64CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {168475A1-982C-4E0B-87ED-6C990D63F180} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {170DFF0D-E314-4D17-A5FC-F2F3F76FEB14} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {18F3D738-B699-42D7-AD7B-2FC923691C42} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-05-29] (Overwolf LTD)
Task: {1FF293A4-FC62-488B-91ED-87558FC37508} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-06-16] (Microsoft Corporation)
Task: {321232E4-8F51-4F08-98F2-59C1870FB821} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {3AD2C6BF-5B25-4E73-897E-BFA192F1ABB5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-29] (Microsoft Corporation)
Task: {3C00F33B-D9AD-430E-8FD4-BB698655855C} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-04-12] (Microsoft Corporation)
Task: {46B16A69-573D-43B6-8DDF-8FF9A6574840} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {57344F61-61B9-4557-80CF-301ACA76318E} - System32\Tasks\avastBCLRestartS-1-5-21-214036272-3329120688-3169881572-1001 => Chrome.exe 
Task: {59D86A16-4EE3-430C-A0C7-D97AF1991301} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-04-12] (Microsoft Corporation)
Task: {67B89A1A-40F4-4451-987B-B81D687345B8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {748E85BE-16B5-4F06-8BB5-64893B554D77} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2013-01-22] ()
Task: {76211712-ACE1-4EA0-96AA-9DA6E60CA0DB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-29] (Microsoft Corporation)
Task: {7EFBF69A-1D16-4E37-B1CA-60AD3DED6D0F} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-03-21] (Acer Incorporated)
Task: {7F28A83F-39A4-4A13-A730-664F2AE27F14} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {83062AFF-8041-4071-85ED-EA29B5FC727C} - System32\Tasks\Pokki => C:\Users\Daniel\AppData\Local\Pokki\Engine\ServiceHostAppUpdater.exe
Task: {8A255254-8789-4A39-A49A-9EC66E9DA3AF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-06-21] (Adobe Systems Incorporated)
Task: {953DDE70-FA26-4828-B05C-DAAFBD206EDB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {98CEEEEC-7421-409E-88EF-F817FC185C1D} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-03-18] (Acer Incorporated)
Task: {A5128015-6529-4464-9126-20B1C3DE490E} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2016-04-12] (Microsoft Corporation)
Task: {B53CCE0B-B830-47FD-A4F2-D599C126167C} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2015-12-01] (Apple Inc.)
Task: {B89835E3-8EE9-48B1-9313-00D1B518202D} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2013-07-08] ()
Task: {B9DB7CDC-3EE6-4279-9C28-6066C58D3FEC} - System32\Tasks\SafeZone scheduled Autoupdate 1453914725 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-04-15] (Avast Software)
Task: {C1965F10-18EF-43D7-AA04-9AFE655BBB72} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {CBFF3795-BEC1-430B-B251-E84F4390EC43} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2014-10-20] (Acer)
Task: {D3EC40FF-5538-4422-A560-A5BCA1CB4E0C} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-03-21] (Acer Incorporate)
Task: {D7DFC437-1F79-4C48-9179-371DDD7A7893} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-03-17] (Acer Incorporate)
Task: {DA15792A-AF32-4439-8986-B4011860D2C1} - System32\Tasks\[email protected] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-05-05] (Adobe Systems Incorporated)
Task: {DB3F2885-7DF8-403B-98AE-13F87EB7775F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-06-15] (AVAST Software)
Task: {DBCC24DB-5284-43AC-B8B5-E1DCD5DC49AA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {DD1011A4-8958-472A-8771-C58A3E23BBB6} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {F5A9F0EB-8870-4273-8FA4-37C356E59C6E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated)
Task: {F6ED17F8-9159-47BF-9E93-DF5EB252A4E1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {F9117665-0257-49FA-90FE-D867C279979B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {FEAE7A90-23EE-4E12-8B39-D261618E9ADA} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-03-21] (Acer Incorporate)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Daniel\Desktop\Person 2 - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\Daniel\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\12192648070.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -contentTile -formatVersion 0x00000002 -pinnedTimeLow 0xaa995a7f -pinnedTimeHigh 0x01ced3cc -securityFlags 0x00000000 -url 0x0000004f hxxp://www.southampton.ac.uk/healthsciencesnet/staffandstudents/timetables.html
ShortcutWithArgument: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Play Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=fahmaaghhglfmonjliepjlchgpgfmobi
ShortcutWithArgument: C:\Users\Public\Desktop\Booking.com.lnk -> C:\Program Files\Booking.COM\StartURL.exe () -> hxxp://www.booking.com/index.html?aid=379334
ShortcutWithArgument: C:\Users\Public\Desktop\PRIVATE WiFi.lnk -> C:\Program Files\PRIVATE WiFi\StartURL.exe () -> hxxp://www.privatewifi.com/partner/clicks.php?pid=928649&bid=76&campaign=default
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-06-07 04:00 - 2012-04-24 11:43 - 00254512 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-11-20 10:35 - 2014-11-20 10:35 - 00225976 _____ () C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe
2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-13 06:45 - 2015-10-13 06:45 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-11-20 11:24 - 2014-11-20 11:24 - 03649720 _____ () C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe
2014-10-02 22:16 - 2016-04-19 19:26 - 00114888 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-04-13 17:54 - 2016-03-29 11:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-11-19 01:24 - 2015-11-19 01:24 - 00415128 _____ () C:\WINDOWS\system32\igfxTray.exe
2016-04-13 17:54 - 2016-03-29 11:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2014-06-07 04:07 - 2014-01-03 14:13 - 00111872 _____ () C:\Program Files (x86)\Acer\clear.fi plug-in\Clearfishellext_x64.dll
2016-05-20 16:58 - 2016-05-20 16:58 - 00959168 _____ () C:\Users\Daniel\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2015-10-29 18:57 - 2015-09-01 17:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-12-18 01:26 - 2015-12-07 05:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-05-12 14:16 - 2016-04-23 05:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-06-16 18:16 - 2016-05-28 04:59 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-06-16 18:16 - 2016-05-28 04:53 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-06-16 18:17 - 2016-05-28 04:54 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-06-16 18:17 - 2016-05-28 04:56 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-06-24 22:57 - 2015-06-24 22:57 - 00133184 _____ () C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
2016-05-16 22:07 - 2016-05-16 22:07 - 00073728 _____ () C:\Program Files (x86)\Dynatrace\LastMile\bin\GomezPEER.exe
2016-04-19 11:47 - 2016-04-19 11:47 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2013-07-08 22:34 - 2013-07-08 22:34 - 04150312 _____ () C:\Program Files (x86)\Acer\Live Updater\updater.exe
2016-06-15 15:47 - 2016-06-15 15:47 - 00123344 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-06-15 15:47 - 2016-06-15 15:47 - 00135816 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-06-16 20:10 - 2016-06-16 20:10 - 02934272 _____ () C:\Program Files\AVAST Software\Avast\defs\16061601\algo.dll
2016-06-15 15:47 - 2016-06-15 15:47 - 00479680 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-06-15 15:47 - 2016-06-15 15:47 - 00309912 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll
2016-06-21 14:24 - 2016-06-21 14:24 - 02939392 _____ () C:\Program Files\AVAST Software\Avast\defs\16062100\algo.dll
2014-11-20 10:30 - 2014-11-20 10:30 - 01147064 _____ () C:\Program Files (x86)\Common Files\VMware\DeviceRedirectionCommon\ftnlapi.dll
2014-06-07 03:40 - 2013-12-10 00:27 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2015-01-07 02:01 - 2015-03-01 15:43 - 01007104 _____ () C:\Program Files (x86)\Origin\platforms\qwindows.dll
2015-01-07 02:01 - 2015-03-01 15:43 - 00023552 _____ () C:\Program Files (x86)\Origin\imageformats\qgif.dll
2015-01-07 02:01 - 2015-03-01 15:43 - 00024576 _____ () C:\Program Files (x86)\Origin\imageformats\qico.dll
2015-01-07 02:01 - 2015-03-01 15:43 - 00216576 _____ () C:\Program Files (x86)\Origin\imageformats\qjpeg.dll
2015-01-07 02:01 - 2015-03-01 15:43 - 00261120 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll
2015-01-07 02:01 - 2015-03-01 15:43 - 00019456 _____ () C:\Program Files (x86)\Origin\imageformats\qtga.dll
2015-01-07 02:01 - 2015-03-01 15:43 - 00337408 _____ () C:\Program Files (x86)\Origin\imageformats\qtiff.dll
2015-01-07 02:01 - 2015-03-01 15:43 - 00018944 _____ () C:\Program Files (x86)\Origin\imageformats\qwbmp.dll
2016-05-20 16:57 - 2016-05-20 16:57 - 00679624 _____ () C:\Users\Daniel\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2014-07-31 12:16 - 2014-07-31 12:16 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2015-10-13 06:45 - 2015-10-13 06:45 - 00237328 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2015-10-13 06:46 - 2015-10-13 06:46 - 01040144 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-10-01 10:23 - 2014-10-01 10:23 - 02140672 _____ () C:\Program Files (x86)\ManyCam\opencv_core2410.dll
2014-10-01 10:24 - 2014-10-01 10:24 - 01891840 _____ () C:\Program Files (x86)\ManyCam\opencv_imgproc2410.dll
2014-10-01 10:25 - 2014-10-01 10:25 - 00654848 _____ () C:\Program Files (x86)\ManyCam\opencv_objdetect2410.dll
2014-10-01 10:24 - 2014-10-01 10:24 - 02147840 _____ () C:\Program Files (x86)\ManyCam\opencv_highgui2410.dll
2014-10-01 10:24 - 2014-10-01 10:24 - 00360960 _____ () C:\Program Files (x86)\ManyCam\opencv_video2410.dll
2016-01-27 02:52 - 2016-01-27 02:52 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-11-16 08:53 - 2014-11-16 08:53 - 00017408 _____ () C:\Program Files (x86)\Dynatrace\LastMile\jre\bin\SystemInfo.dll
2016-06-15 23:28 - 2016-06-15 23:28 - 02593168 _____ () C:\Users\Daniel\AppData\Local\Temp\SevenZipJBinding-N8q7X\lib7-Zip-JBinding.dll
2014-11-16 08:53 - 2014-11-16 08:53 - 00055808 _____ () C:\Program Files (x86)\Dynatrace\LastMile\jre\bin\ICE_JNIRegistry.dll
2016-06-21 00:31 - 2016-06-15 10:15 - 01745560 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libglesv2.dll
2016-06-21 00:31 - 2016-06-15 10:15 - 00091288 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\libegl.dll
2016-04-19 11:47 - 2016-04-19 11:47 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-19 11:47 - 2016-04-19 11:47 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-10-29 18:57 - 2015-09-01 13:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
2016-06-21 00:31 - 2016-06-15 10:15 - 17599640 _____ () C:\Program Files (x86)\Google\Chrome\Application\51.0.2704.103\PepperFlash\pepflashplayer.dll
2016-02-23 15:04 - 2016-02-23 15:04 - 00325824 _____ () C:\Program Files\Microsoft Office 15\root\Office15\AppVIsvStream32.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 194.168.4.100 - 194.168.8.100
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\Run32: => "BacKGround Agent"
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\StartupApproved\Run: => "AcerPortal"
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\...\StartupApproved\Run: => "Overwolf"
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "AcerPortal"
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Overwolf"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{D160EFC1-7DAF-4914-A46F-1923296D2789}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{21C4175A-7FF2-4202-8324-7C897758DFFB}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
FirewallRules: [{EB454143-A965-44B8-8EA1-7B61CE2AC6AD}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{624FAC64-EA30-4430-A8EF-F38957024F36}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
FirewallRules: [{A74C75CA-B8B1-47C0-9C53-031072D2C03B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Frozen Endzone\FrozenEndzone.exe
FirewallRules: [{43910E7D-9EBE-47B4-B163-15472E45647B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Frozen Endzone\FrozenEndzone.exe
FirewallRules: [{9AE8A2D9-DC64-4642-9FC4-B7C6D534C17A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Ship\ship.exe
FirewallRules: [{7F6DA6F4-B743-41EB-A408-080F25CA0AF5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Ship\ship.exe
FirewallRules: [UDP Query User{47EE68A8-3544-46CB-B09B-E5EB491AAC6A}C:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_tablet.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_tablet.exe
FirewallRules: [TCP Query User{B06ACD50-D5DA-490A-B9E6-F806DCE34458}C:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_tablet.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_tablet.exe
FirewallRules: [{398CF81B-D4BE-4BFB-8062-9DC43C83C1FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Railroads\RailRoads.exe
FirewallRules: [{A91D1AAE-5F19-402E-8CD8-E35B3C3C8703}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Railroads\RailRoads.exe
FirewallRules: [{D9345E12-CFE7-476D-80AF-104BDD601FA9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{36351C17-C366-412C-BFAD-521430E50576}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\FTL Faster Than Light\FTLGame.exe
FirewallRules: [{D4C38FD2-F5E2-4267-AEEF-89291BB3EBF4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A2E55E05-E7F1-49F9-9335-110F48F55014}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DE9259FF-9B8A-422F-AA96-9D04BB4F2712}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{94F633F1-4DD4-4633-8E7D-8B3336E80E6C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6E27D2E9-514F-42AE-AAD4-3B973F4D91FD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{25653548-A7D3-442D-9AD0-5215F81B77C3}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{FD01C58B-BE83-4292-9C8A-15A552551701}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dream\Binaries\Win32\Dream.exe
FirewallRules: [{7F622304-655F-457C-9352-990EC3569AE4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dream\Binaries\Win32\Dream.exe
FirewallRules: [UDP Query User{BAEBF806-4763-4A04-8BCE-BACC408C121C}C:\program files (x86)\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe
FirewallRules: [TCP Query User{89DE7A14-C43E-455D-91E4-E79882D70639}C:\program files (x86)\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\orcs must die 2\build\game\orcsmustdie2.exe
FirewallRules: [{D30DCC3F-FBFB-497F-8204-EB8525B9733B}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{D43B8C4F-2A3A-4C6C-8A70-642F2F33E99C}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{DFB5BBB6-1422-41E6-A689-D9F6DEBC41CE}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{83A949DB-D2DC-4852-A61B-54A2F67BF886}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{73FFFC33-D2BD-4668-92AC-FD86166A8F1D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{9D0131C8-522F-4C87-B378-2634C483DCDB}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{8F456B46-EC8B-43CC-BA47-72BB961308CA}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{98AA7497-E37D-4367-9799-81D5E9D53AB2}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{1F1DA3D8-1F2E-4D35-869A-83FCE8D6C4A9}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{FBCCE9DF-91D3-49FE-9B10-D3C271856E4B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{AC955742-24E7-4EA5-A279-BEDC8F43CE8D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{6D8E99A2-A15F-46D9-9D4D-F60FFFBCEDD3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{BE57186E-9255-4BE5-B89B-31672B54104B}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{52E3ACA5-C63F-45AC-8F96-515607476685}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{1F11B64D-28C0-4218-A1C3-D63F848E14F4}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{51B6341F-330C-4D4E-A5FA-D8FE08800D68}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{46141551-B0BD-4DD8-AA72-2BE4C46F73B6}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{F41FA72A-3082-48D1-A799-79B64D116769}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{DB60759F-98AC-4FDF-9279-3F59406D944D}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{38321B4F-4551-41CE-A8A5-708AA8C8A37F}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{646DAEA7-DDCC-4600-A3BB-E3C27CF443AB}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\DMCDaemon.exe
FirewallRules: [{E42B9FE8-78F8-476F-9ED8-7BDE4FC35AAF}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{ADA45E8A-0360-4C9E-B63C-6B4B401A8B43}] => (Allow) C:\Program Files (x86)\Acer\Acer Media\WindowsUpnpMV.exe
FirewallRules: [{EA440325-659F-4259-A5F5-870DB2E6403C}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{8B20A330-5BEC-4690-96F5-BBCA5885F104}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{883D403D-2CA3-4C88-9391-24A5E6823AE4}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{05FC9238-C780-486D-AACC-61881BBED1D3}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{008225C4-6D5A-40E7-86E7-31A4BFF73C04}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{FD89DE93-D531-4573-901D-36A7B08D9CF1}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\DMCDaemon.exe
FirewallRules: [{D95C14BF-9865-44B5-BF4C-C4ACD36FF970}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{54946B32-01C1-4247-B659-3B18CA3485E1}] => (Allow) C:\Program Files (x86)\Acer\Acer Photo\WindowsUpnp.exe
FirewallRules: [{EB5B1519-6D52-4772-AB69-8F5241BF3226}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{7F007A61-EE15-47C1-B54A-973651FF460B}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{6009B135-9B03-47A7-877A-3C83B08E49FD}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\Sdd.exe
FirewallRules: [{0FAC20A9-7FD6-4C43-B8CA-D6407544A08F}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\Sdd.exe
FirewallRules: [{A4461AE3-E1FF-475B-814E-CC5BE4C66AC1}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\virtualdrive.exe
FirewallRules: [{E3A05E7A-B12D-492A-A04D-760EFE5E57BD}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\virtualdrive.exe
FirewallRules: [{3BC0A71A-01A0-4A3F-AEA9-53222E39BC43}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{E51458B9-4A39-4F32-A72D-156D05BABD6C}] => (Allow) C:\Program Files (x86)\Acer\Acer Portal\ccd.exe
FirewallRules: [{51D3B1ED-1A11-441B-A8EE-F0DDC47EC7F5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{BDDF8BC9-7FB3-4089-B208-3997C21B4CD8}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{19EFA2CB-762D-4E10-B7EE-E3C460BA6C84}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{0E77E029-B6B8-4640-8B09-7AF7582D3EDD}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{5F490AB3-9D9F-4927-A7AA-369145A9B3F8}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{94A03E93-25B6-44C0-BAB2-BD2DE0150BDA}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{2098CEF1-FF1F-4F7E-BE6D-8B211562BE84}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{DD110350-877E-4472-9053-69FE0B7296D1}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{A62003CD-B02C-4D9D-B861-5546A63D7B34}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{594A37C7-A6F7-482B-A3C6-2AC95EF108C6}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{0639339F-5807-4C07-8FD7-7C074E217938}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{15A80A74-2516-4E3E-856A-BCAB3C27213A}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{B2A972A4-F35B-4376-936A-E064C4DDDB0A}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{BCD76905-F81A-41EF-883C-82D649A45EB9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{F77D6237-EA7A-44E1-8E8E-AD53DF29A7A9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{3033A5B0-4186-4582-917E-59D9133D4359}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{DEA45E91-1360-4EAA-A76F-A4C292A33050}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{EFB41739-C8C3-4853-893C-F81F85BF910C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{660781BE-50C6-43EC-9088-31050F5AAAFD}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{4C8F8CA5-1A49-4048-ACAE-4ABD2A2F4101}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{A27AC8F5-2673-4600-AB4D-7631824B4895}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{892CD237-C879-4665-9E58-9EBC432C60F0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{6BFD42FF-CA16-42E6-849B-E698D3A22C0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{EBADA2B4-D86A-4281-96B5-6B8DEDADEF45}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{A0626E00-E697-4D06-8D46-C41C9A366463}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{126CFE9E-F34C-439E-B739-F684DD745AD0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{AF4D3A42-C5CF-4A58-B420-A7A73B91AE02}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{818FF5C6-8164-4D78-95F9-F496BF3D8D6C}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{844CD833-B87F-4F4B-B2E8-A44A73529456}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{39A01B6E-68C9-4E06-99FF-F88217C2820B}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{5EC158AB-72AA-4906-A849-EB1F617329DB}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{DB1F9018-2E9D-42CB-BFDB-26FD80A44C75}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{8346A57E-9138-4B92-9B63-FB334E9E1411}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{9ED104A5-3D34-43DB-8752-227460488B9C}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{AB02F5F9-6B54-4E8B-B4CE-CD48C75B04FA}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{C3DE3BFB-AF6F-4359-87A5-2DEC8D944CA1}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{60697ED2-B1AA-4B9C-91B8-E70249548B27}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{53351F16-5515-4010-862A-E559A452EE28}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{4037B30E-38C3-4C28-8462-25F0AD2D5241}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{07655BC7-6480-4A32-B1AE-9670D70541EF}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{7128EBF3-718E-4C4C-A799-79D10E6C3149}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{551945D0-BE74-49C2-97FD-AE40BFD883D2}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{69502ADA-21D6-4777-B76A-995B6543D946}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{6FD102B0-8AC9-441C-9217-99DDB6BA9989}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{D18C1B76-9B0A-4FCE-9FB5-C35F9129EFFA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{9131A4D2-8572-416E-91A9-283BB0B87D4F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Orcs Must Die 2\build\release\OrcsMustDie2.exe
FirewallRules: [{E2316C8D-30F8-4102-B2F7-9A522B72132E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Orcs Must Die 2\build\release\OrcsMustDie2.exe
FirewallRules: [{86A790F3-3E0E-4B2C-A3D0-6D3ED10611DC}] => (Allow) C:\Program Files (x86)\GameforgeLive\gfl_client.exe
FirewallRules: [{569619D5-EF78-4E34-8529-547906EF540F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Crash Time II\BurningWheels.exe
FirewallRules: [{97414306-2BCD-453F-B934-F1186C19994B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Crash Time II\BurningWheels.exe
FirewallRules: [{942E3580-8A92-49CE-B66C-1707C99C72A5}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{5DA77F81-C07B-4ED6-9391-FE96F48FD6CD}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{A10406DF-521E-4C27-AAA0-6EB9443ADFDC}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{9C2D5C3B-636B-4B7D-BC98-4D665033E877}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{35369788-0751-4A25-9061-FCFFAC727E09}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{B04B52A8-74CB-4578-9C9E-F8A435F67B0D}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\DMCDaemon.exe
FirewallRules: [{9D6F059B-6F4F-4753-BC55-12B387A81313}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{FDFE2D69-FE74-4F61-BF61-00CB720E5356}] => (Allow) C:\Program Files (x86)\Acer\abMedia_\WindowsUpnpMV.exe
FirewallRules: [{B874FE8D-5E5B-4642-8754-DD32D434171D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{DC711637-E23C-44A8-8B49-A8B15DD6CA7E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{CC8B3542-78D5-42E2-A9E0-253FE5806D5A}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{05880AA5-CC3D-44D1-9E58-C35B78F7AB4C}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{5744598D-D187-45DD-A746-8A29DA79BC2E}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{49DD0CF4-8D9A-463F-9335-7CD9EA9F9F1D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{9F38FD16-F878-4D78-B358-408ECB52877A}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{48CC54C3-2309-4C8D-A04D-60B8F0958462}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{3631D532-9CD0-4EBD-95C0-6426838E6AA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_DX11.exe
FirewallRules: [{1DC52135-438C-4808-BE27-35202FAF902D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_DX11.exe
FirewallRules: [{C1C7764F-D02F-46C3-9FDE-7DEDAEA0920D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_Mantle.exe
FirewallRules: [{F517269A-C4C3-4171-AA45-A8854456B57B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization Beyond Earth\CivilizationBE_Mantle.exe
FirewallRules: [{41912F80-97D2-482D-805F-0487D600583C}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{00F81E73-4C6B-4105-A47C-5980844C1DFF}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{395AE704-D2EE-4241-938E-D2F2134A01E3}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{9574A228-4201-42EE-90DC-4FD86CA1639C}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{659CBBBB-3686-4CD6-B996-6BD79A1C1546}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{EB32FE58-81C2-4F20-B80C-2F91FE9B0137}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect.exe
FirewallRules: [TCP Query User{D396F96A-3AA2-415A-AC00-AC9515346ECD}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{49623B83-EB8A-47AB-88BC-C2AB63EB0FF3}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{391EB01D-3745-45B3-BC2A-0C98457730A1}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{A5A4F80C-E750-4733-85D6-C8AA1BF0B3DC}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{59868E3C-BF10-42D1-9C16-6989F11431F2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\iambread\IamBread.exe
FirewallRules: [{C6959A45-07D8-4715-B873-0A7C5B52AA53}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\iambread\IamBread.exe
FirewallRules: [{D5D2F235-8134-467C-BB08-EDE117AAA648}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Speedball 2 HD\Speedball2_steam.exe
FirewallRules: [{B66520CC-0E0E-4159-9798-A99F558B1241}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Speedball 2 HD\Speedball2_steam.exe
FirewallRules: [{A5F5B027-A582-4816-8840-0A348EB7E3EE}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{D8D6B16F-D72C-45EB-BD6E-0465CA6596EE}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [TCP Query User{F510745A-A5DB-4330-B025-F27DAAA808D8}C:\users\daniel\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\daniel\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{2C2C9405-D9F7-413C-893C-F7BB59A54AF5}C:\users\daniel\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\daniel\appdata\roaming\spotify\spotify.exe
FirewallRules: [{4DEE6F58-C1F7-49ED-BEE8-F33DAFB6E858}] => (Allow) C:\Program Files (x86)\Origin Games\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{99EB4E33-A008-4D0E-9797-98FA121ADCB5}] => (Allow) C:\Program Files (x86)\Origin Games\Theme Hospital\data\Game\DOSBox\LAUNCHER.exe
FirewallRules: [{4501AA64-DA4F-443C-AA3A-3ADA15514BF2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Battlespace\BattleSpace.exe
FirewallRules: [{B0DAF77D-25FD-4663-88B7-77F86A2AC98F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Battlespace\BattleSpace.exe
FirewallRules: [TCP Query User{78B4723C-A5EC-4DDE-9BEB-7742C26BDAFB}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{FDB7A2DE-E247-4398-855D-10BD82E2F7F1}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{892E1B95-FEA1-41B8-805E-F0870D0128A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Besiege\Besiege.exe
FirewallRules: [{359C47B8-0784-4079-B7BB-79AD56D226BF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Besiege\Besiege.exe
FirewallRules: [{CA995D80-A84E-4047-8257-13D189FDC146}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Banished\Application-steam-x64.exe
FirewallRules: [{CEE2FD09-D617-434B-9BA8-0DAD8EF71A1D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Banished\Application-steam-x64.exe
FirewallRules: [{9A579C57-1705-4250-B0C6-B8C3D11AFBE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{86B98E12-A03D-49AD-904C-89435C5A2621}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{6F98A5F4-6C81-4DED-B8A7-B18B619B27FC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King Arthur's Gold\KAG.exe
FirewallRules: [{0841E31D-5E8E-43E0-A038-E3AFD7C11EDA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King Arthur's Gold\KAG.exe
FirewallRules: [TCP Query User{12CC0861-C105-4DC5-BF72-2258F49A9464}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{74B7F990-6254-4D69-88CA-9A8CC0259871}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{A377BED2-8DF5-4918-9A0A-3599E7D2681A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ProjectZomboid\ProjectZomboid32.exe
FirewallRules: [{4E48A326-8460-49C8-8013-B0D725F1A241}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ProjectZomboid\ProjectZomboid32.exe
FirewallRules: [{EF10BD8E-D4EB-400B-8CE0-23EC37BCDDF9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ProjectZomboid\ProjectZomboid64.exe
FirewallRules: [{69F17729-5B18-41B2-AD8A-37E7AA0C3E16}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\ProjectZomboid\ProjectZomboid64.exe
FirewallRules: [{EEEBE15F-DC6D-4B72-884B-9DCB0813E6D0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Escapists\TheEscapists.exe
FirewallRules: [{9EC61476-5F1B-48B2-A5B4-F8CA06450A80}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Escapists\TheEscapists.exe
FirewallRules: [{311D1A6E-AC06-4BB3-BD35-70D0B73A87A3}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe
FirewallRules: [{BB9415E7-850A-45A3-AF67-00C0A68D16F7}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe
FirewallRules: [{6316AD0F-F5B2-4221-8031-CDF2BCBA0199}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe
FirewallRules: [{F2B28641-D96D-4B33-BAD4-FBBEF1AA1E30}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-remotemks.exe
FirewallRules: [{BE610861-55F8-45B9-876D-EDDE4181E630}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe
FirewallRules: [{30D8E72D-26AF-4B1B-9697-E72FC59F825D}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe
FirewallRules: [{AE13BF83-FF0F-4D15-94E4-90F7A3781CBA}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe
FirewallRules: [{D0E0A849-AA5B-40F3-82C1-3CA6EA3B5C84}] => (Allow) C:\Program Files (x86)\VMware\VMware Horizon View Client\vmware-view.exe
FirewallRules: [{6ED6C36D-9C48-4093-BDB1-1AC3DC96024E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hoard\win32\Reuben.exe
FirewallRules: [{B7464E8E-2DC3-4AA7-BA6B-A603049AED37}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hoard\win32\Reuben.exe
FirewallRules: [{C4F671A4-7B77-4032-866C-1520450C1A84}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\planets under attack\game.exe
FirewallRules: [{04A80D9B-B590-4422-A225-A446E82782BC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\planets under attack\game.exe
FirewallRules: [{AB8D1ECB-52B3-4C66-BCAF-A914BB392C4C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\X-Blades\launcher.exe
FirewallRules: [{3E5092E2-1FA2-43E9-B146-30C2D9A8D53A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\X-Blades\launcher.exe
FirewallRules: [{D341F35B-5287-42C5-8E8D-F226C135C134}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rune Classic\System\Rune.exe
FirewallRules: [{7B3BDCF4-F605-4CDD-86ED-3BFA054455A8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rune Classic\System\Rune.exe
FirewallRules: [{9AB3DFF8-6189-4EE1-AB79-FCC8B1CE3118}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Knights and Merchants Historical Version\KM_TPR.exe
FirewallRules: [{D5834E36-18D9-4CDB-94E2-F330CBDEFC6C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Knights and Merchants Historical Version\KM_TPR.exe
FirewallRules: [{CD7CF6B4-1849-4C1E-90D6-EE69200C4C3B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Knights and Merchants Historical Version\hd\Knights_and_Merchants_steam.exe
FirewallRules: [{33B87BFB-D7F8-45ED-B8F5-B62A412FD612}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Knights and Merchants Historical Version\hd\Knights_and_Merchants_steam.exe
FirewallRules: [{D01DFCEF-5001-4A17-9F47-C89CD2D6F0CF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Cities_Skylines\Cities.exe
FirewallRules: [{D9BFC5F3-8510-43C2-BBA9-12F90ECD7AC5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Cities_Skylines\Cities.exe
FirewallRules: [{5A609E6F-0A95-4CBC-999D-6D58547579E0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game Dev Tycoon\nw.exe
FirewallRules: [{17247385-AF37-49AF-BBFA-D534121C996A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Game Dev Tycoon\nw.exe
FirewallRules: [{B55F5EEE-1F8E-4093-BAA7-4CA923B4378F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Wars Battlefront II\GameData\BattlefrontII.exe
FirewallRules: [{07689AB6-E742-4545-9911-42BD82285DE3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Wars Battlefront II\GameData\BattlefrontII.exe
FirewallRules: [TCP Query User{8FB902C0-4542-446C-81E1-45CC8FDF5411}C:\users\daniel\appdata\roaming\gameranger\gameranger\gameranger.exe] => (Allow) C:\users\daniel\appdata\roaming\gameranger\gameranger\gameranger.exe
FirewallRules: [UDP Query User{8487C25C-27E5-49C8-A9BE-74A3DB8EB1DF}C:\users\daniel\appdata\roaming\gameranger\gameranger\gameranger.exe] => (Allow) C:\users\daniel\appdata\roaming\gameranger\gameranger\gameranger.exe
FirewallRules: [{395424B3-0E41-46B1-AE37-98FAE3EABDA3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Wars Empire at War\runme.exe
FirewallRules: [{263F05B3-4193-4BA8-9D96-CA7900452BB3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Wars Empire at War\runme.exe
FirewallRules: [{D49D6D8B-4413-4BFD-97FF-E6981EE6926E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Wars Empire at War\runme2.exe
FirewallRules: [{7ACF5A27-75CB-4299-BA8D-BFCB457BE2A3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Star Wars Empire at War\runme2.exe
FirewallRules: [TCP Query User{D5B73894-2657-4074-B242-AFF33CF6FE40}C:\program files (x86)\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe
FirewallRules: [UDP Query User{5F562508-C110-42A3-8893-CD7586C2E135}C:\program files (x86)\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\star wars empire at war\gamedata\sweaw.exe
FirewallRules: [TCP Query User{B6F753D3-F232-41C2-88F0-AC08CB405FE5}C:\program files (x86)\steam\steamapps\common\star wars empire at war\corruption\swfoc.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\star wars empire at war\corruption\swfoc.exe
FirewallRules: [UDP Query User{0698D3BF-8021-48D8-BC2A-36360E822D69}C:\program files (x86)\steam\steamapps\common\star wars empire at war\corruption\swfoc.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\star wars empire at war\corruption\swfoc.exe
FirewallRules: [{6A31DABF-4F3A-4839-8DF4-83D65787B561}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MedievalEngineers\Bin64\MedievalEngineers.exe
FirewallRules: [{868C35EA-EDE3-4F7D-80E1-07E319F5B973}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MedievalEngineers\Bin64\MedievalEngineers.exe
FirewallRules: [{E8EB0222-6201-4E8B-A6BD-F85B4654552F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\StarMade\StarMade-starter.exe
FirewallRules: [{5F5392BE-5A6B-40DA-9EC8-04C8401FC8BF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\StarMade\StarMade-starter.exe
FirewallRules: [TCP Query User{A888F93D-538F-4FED-AA9D-CBE24C1D9C65}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{A4B31C2E-3717-40CC-A076-3A43D38124C4}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{BE4C9212-79DA-4AEA-B9FA-3B82DBD2EBC9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{82F5F46A-3358-4055-8F29-AFABBEDBB7DC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{109612DC-D0D1-4F9E-B2E2-507D94679D2B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Interplanetary\Interplanetary.exe
FirewallRules: [{5EEDFBC9-200D-4C7B-9EF8-EEB43659885D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Interplanetary\Interplanetary.exe
FirewallRules: [{FF07BF84-1945-493B-92F0-DC34B49AC360}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{3765DBDB-609B-490B-8DB5-4C3585FDBACA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Forest\TheForest.exe
FirewallRules: [{D1B7A665-01F5-4708-9D5B-2D9A9FB02BFD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dream\_Rift\Binaries\Win32\DreamRift.exe
FirewallRules: [{83D44EA8-F3BE-4CB2-B9F8-94F73CC46FF8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dream\_Rift\Binaries\Win32\DreamRift.exe
FirewallRules: [{954F0524-E49B-4E93-866C-0AA58267A408}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{BC36B7B6-DE7F-496F-BCC7-E208A8DB692C}] => (Allow) C:\Program Files (x86)\Origin Games\The Sims 4\Game\Bin\TS4.exe
FirewallRules: [{3A06AC58-8EE1-4DAE-9CF6-F5DC2D0FA0E9}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{F51E7385-CF8F-4B88-82AB-D541388A5B96}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{44C3E304-7E2C-4A09-A8E0-655D54369C3C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{5A1724F2-2CC4-4DC5-A401-EC6EF26ED6C6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{2818AA2C-7466-441D-AB7F-E8BF23CE1634}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{F4C9B21D-4AF0-4631-A7E2-BA3832EB5BF3}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{04C65F5A-E9D6-49BB-9D3D-FF5DB5B50F12}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [{C1296F48-202C-45EB-9DF0-163C7AAB8C8F}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
FirewallRules: [{DFAC9CA7-8822-4E24-8575-313B8C22DE11}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
FirewallRules: [TCP Query User{903DA307-7025-49B4-901B-93E853C1A581}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{CEED2620-F52A-47CA-B40D-50E5DE336711}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [TCP Query User{275F8AC9-A99C-4FA9-BF8B-21C4811B5A09}C:\users\daniel\documents\ethereum-wallet-win64-0-5-2\resources\node\geth\geth.exe] => (Allow) C:\users\daniel\documents\ethereum-wallet-win64-0-5-2\resources\node\geth\geth.exe
FirewallRules: [UDP Query User{899F4C31-0D20-4DA9-B360-FE293BE5054A}C:\users\daniel\documents\ethereum-wallet-win64-0-5-2\resources\node\geth\geth.exe] => (Allow) C:\users\daniel\documents\ethereum-wallet-win64-0-5-2\resources\node\geth\geth.exe
FirewallRules: [{40CE736B-0FE1-46B8-840E-BC4BABE6021F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Jackbox Party Pack 2\The Jackbox Party Pack 2.exe
FirewallRules: [{8257CE23-FD5B-49A9-A734-C79957BC95AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Jackbox Party Pack 2\The Jackbox Party Pack 2.exe
FirewallRules: [TCP Query User{EDA09A53-C019-4C36-8E97-428B3BD95139}C:\users\daniel\appdata\local\skypeplugin\7.17.0.43\pluginhost.exe] => (Allow) C:\users\daniel\appdata\local\skypeplugin\7.17.0.43\pluginhost.exe
FirewallRules: [UDP Query User{0AC8C3F5-CB9C-4DB8-87D2-29F59E5AA5D8}C:\users\daniel\appdata\local\skypeplugin\7.17.0.43\pluginhost.exe] => (Allow) C:\users\daniel\appdata\local\skypeplugin\7.17.0.43\pluginhost.exe
FirewallRules: [{8848542B-1C53-47F1-AD82-A847E46ED5D3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect Safe Mode.exe
FirewallRules: [{74E441AB-65C9-47EA-9995-AD91E3EA5DEB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Prison Architect\Prison Architect Safe Mode.exe
FirewallRules: [{A3640960-78DA-42A2-8750-13F9D7304BF6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Scrap Mechanic\Release\ScrapMechanic.exe
FirewallRules: [{9B81B25F-A757-43A8-9F0E-DE2674B86946}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Scrap Mechanic\Release\ScrapMechanic.exe
FirewallRules: [{5BEFAE39-1144-4A1B-9455-BA8FF05BF121}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\StarMade\starmade-launcher.exe
FirewallRules: [{5C0BD7CA-7FDE-4786-BD30-7B7630FD5301}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\StarMade\starmade-launcher.exe
FirewallRules: [{B4F6326D-2EFF-48C0-9FC6-F1958A717C97}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Kerbal Space Program\KSP_x64.exe
FirewallRules: [{3AADDF66-02ED-4DC6-9320-805A77F6DB30}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Kerbal Space Program\KSP_x64.exe
FirewallRules: [TCP Query User{C6676CBA-6B49-42D3-86E4-AD1096A56836}C:\program files (x86)\dynatrace\lastmile\agents\gozilla\runtime\gozilla.exe] => (Allow) C:\program files (x86)\dynatrace\lastmile\agents\gozilla\runtime\gozilla.exe
FirewallRules: [UDP Query User{77318732-5EE1-4A3E-AA5B-84A518FE13A2}C:\program files (x86)\dynatrace\lastmile\agents\gozilla\runtime\gozilla.exe] => (Allow) C:\program files (x86)\dynatrace\lastmile\agents\gozilla\runtime\gozilla.exe
FirewallRules: [TCP Query User{62C3D8C1-64D3-45D2-B36B-0FAF126FFF26}C:\program files\litecoin\litecoin-qt.exe] => (Allow) C:\program files\litecoin\litecoin-qt.exe
FirewallRules: [UDP Query User{5873C297-5991-4240-9DC5-C1E3A51CB3AC}C:\program files\litecoin\litecoin-qt.exe] => (Allow) C:\program files\litecoin\litecoin-qt.exe
FirewallRules: [TCP Query User{843B47E2-D822-49B4-A99D-34F3CF748AE3}C:\program files\bitcoin\bitcoin-qt.exe] => (Allow) C:\program files\bitcoin\bitcoin-qt.exe
FirewallRules: [UDP Query User{B9AFB62F-A2FC-4473-ADEE-AE62CBDCC9B2}C:\program files\bitcoin\bitcoin-qt.exe] => (Allow) C:\program files\bitcoin\bitcoin-qt.exe
FirewallRules: [TCP Query User{5535EF75-A4CB-4836-B7DB-E86551AF1E79}C:\program files (x86)\dynatrace\lastmile\agents\gozilla\runtime\gozilla.exe] => (Allow) C:\program files (x86)\dynatrace\lastmile\agents\gozilla\runtime\gozilla.exe
FirewallRules: [UDP Query User{4F5131D6-72C7-4077-BA1B-4465AC723369}C:\program files (x86)\dynatrace\lastmile\agents\gozilla\runtime\gozilla.exe] => (Allow) C:\program files (x86)\dynatrace\lastmile\agents\gozilla\runtime\gozilla.exe
FirewallRules: [{F2FB36A8-F713-445C-88F8-4B8695E4BDA1}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
27-05-2016 19:34:17 Scheduled Checkpoint
09-06-2016 05:44:27 Scheduled Checkpoint
13-06-2016 11:33:12 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918
16-06-2016 21:07:58 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/21/2016 02:45:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: {BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe, version: 3.1.0.9, time stamp: 0x566b28d2
Faulting module name: {BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe, version: 3.1.0.9, time stamp: 0x566b28d2
Exception code: 0x40000015
Fault offset: 0x0014321c
Faulting process ID: 0x1ed0
Faulting application start time: 0x{BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe0
Faulting application path: {BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe1
Faulting module path: {BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe2
Report ID: {BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe3
Faulting package full name: {BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe4
Faulting package-relative application ID: {BEEFB832-3F93-4904-9429-CC0B0F80F02F}.exe5
 
Error: (06/21/2016 12:39:27 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12922
 
Error: (06/21/2016 12:39:27 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 12922
 
Error: (06/21/2016 12:39:27 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/17/2016 07:38:47 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_8c15ae12515e1c22.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10586.0_none_d3c2e4e965da4528.manifest.
 
Error: (06/17/2016 07:38:16 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: BISMILLAH)
Description: Activation of application Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2147009280 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (06/16/2016 09:10:59 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (06/16/2016 08:04:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname Bismillah.local already in use; will try Bismillah-2.local instead
 
Error: (06/16/2016 08:04:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 1; will deregister   16 Bismillah.local. AAAA FE80:0000:0000:0000:D075:EB39:1506:793E
 
Error: (06/16/2016 08:04:05 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from FE80:0000:0000:0000:D075:EB39:1506:793E:5353    4 Bismillah.local. Addr 192.168.0.5
 
 
System errors:
=============
Error: (06/21/2016 02:27:43 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}
 
Error: (06/21/2016 12:39:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Sync Host_9b056d service to connect.
 
Error: (06/21/2016 12:39:03 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the User Data Storage_9b056d service to connect.
 
Error: (06/21/2016 12:39:03 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the User Data Storage_9b056d service, but this action failed with the following error: 
%%1056 = An instance of the service is already running.
 
 
Error: (06/21/2016 12:38:53 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_9b056d service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (06/21/2016 12:38:53 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_9b056d service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (06/21/2016 12:38:53 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_9b056d service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (06/21/2016 12:38:53 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_9b056d service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (06/21/2016 12:38:52 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (06/21/2016 12:07:53 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}
 
 
CodeIntegrity:
===================================
  Date: 2016-06-21 00:03:59.874
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-06-17 18:56:25.269
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-06-16 21:31:55.176
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-06-03 15:14:31.080
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-22 00:20:10.623
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-20 17:23:00.978
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-15 20:19:19.093
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-13 17:54:28.414
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-05-04 19:03:50.478
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-04-19 18:29:08.746
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-4210U CPU @ 1.70GHz
Percentage of memory in use: 85%
Total physical RAM: 3987.27 MB
Available physical RAM: 581.14 MB
Total Virtual: 8851.27 MB
Available Virtual: 3651.51 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:914.18 GB) (Free:635.03 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 560E3A35)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 

  • 0

Advertisements


#2
Bruce1270

Bruce1270

    Trusted Helper

  • Malware Removal
  • 1,714 posts
Hello Wolfman360 and :welcome:

My name is Bruce1270 and I will be helping you with your malware problem.

A few things before we get started.
  • Please read all instructions carefully. If there is anything you do not understand please ask me first before doing anything.
  • Please be patient. I am a volunteer who does this in my spare time so I will try to get back to you as soon as possible.
  • Please follow all instructions in the order given.
  • Please do not install any other software unless advised. This may hinder the removal process.
  • At the top of your post, please click on the "Follow this topic" button and make sure that the "Received notification" box is checked and set to "Instantly" This will send an email to you as soon as I reply to your topic, allowing us to solve your problem faster.
  • Please make sure you reply within 4 days to my responses, if there is no reply within 4 days, the topic will be closed and you will need to request the topic be reopened.


    Important!

    Please save or print off these instructions. Part of this fix may require you to be in safe mode where you will not be able to access the internet or my instructions!

    I would strongly recommend you back up your personal data and folders before we begin.

    Malware removal can be very long, complicated and may take multiple steps. I understand this may be frustrating but please stay with this topic until your machine is declared clean. The results will hopefully be very rewarding. :happy:
    As we go along please tell me how the computer is running now. Please be as descriptive as possible e.g. I'm still getting web redirects, I am unable to access the internet etc.

    OK. Let's move on.

    I'll have a look through the logs posted and come back with some further insructions. :)

  • 0

#3
Bruce1270

Bruce1270

    Trusted Helper

  • Malware Removal
  • 1,714 posts
Hi Wolfman360

Not seeing much but we can tidy a few things up.

First some advice

P2P Warning: !

IMPORTANT I have noticed that there are signs of P2P (Peer to Peer) File Sharing Program on your computer.

As long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur.

Once upon a time, P2P file sharing was fairly safe. This is no longer true. P2P programs form a direct conduit inside your computer, their security measures are easily circumvented, and malware writers are increasingly exploiting them to spread their wares on to your computer. If your P2P program is not configured correctly, your computer may also be sharing more files than you realize. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to a file sharing network by a badly configured program.

Please read these short reports on the dangers of peer-2-peer programs and file sharing.

Risks of Peer to Peer systems
P2P programs: Popular and perilous

If you continue to use P2P programs it is likely that you will get infected again.

I would recommend that you uninstall them, however that choice is up to you.
If you decide to keep the programs in spite of the risks involved, do not use them until I have finished cleaning your computer and have given you the all clear.


Step1 - uninstall programs

Please uninstall the following unwanted programs:

YTD Video Downloader 4.8.9


Optional Uninstall

Pokki
Pokki start menu


Pokki itself is not malicious but is often bundled with other 3rd party software and can be unknowingly installed. Your choice whether to keep or not. :)

To do this:
right-click the Start button and click Control Panel. Go to Programs and Features (if your Control Panel is in Category view, go to Uninstall a Program).
Find the program you want to uninstall, click it to select it, and then click Uninstall.


Step2 - FRST fix

I noticed that you run FRST64.exe from Users\\Downloads folder. Please move it to your Desktop. You can do it by right-clicking FRST64.exe, click Cut, then go to Desktop, right-click any free space and click Paste. For the FRST fix to work both FRST64.exe and fixlist.txt must be in the same location and the desktop is where the software is most effective from.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint:
HKU\S-1-5-21-214036272-3329120688-3169881572-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-214036272-3329120688-3169881572-1001 -> DefaultScope {EAD469F4-AA29-11E4-8274-F8A9639CDE48} URL =
SearchScopes: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {EAD469F4-AA29-11E4-8274-F8A9639CDE48} URL =
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - No File
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor => not found
CHR HomePage: Default -> hxxp://homepage-web.com/?s=acer&m=home
CHR StartupUrls: Default -> "hxxp://homepage-web.com/?s=acer&m=start"
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-170F5F5A3E94}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-214036272-3329120688-3169881572-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-170F5F5A3E94}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
Task: {017C94E1-A077-418E-BA81-7EE616B4CF28} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {06D1AF14-B4E9-46FB-B6FA-6521A6FF64CE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {321232E4-8F51-4F08-98F2-59C1870FB821} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {46B16A69-573D-43B6-8DDF-8FF9A6574840} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {67B89A1A-40F4-4451-987B-B81D687345B8} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {7F28A83F-39A4-4A13-A730-664F2AE27F14} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {953DDE70-FA26-4828-B05C-DAAFBD206EDB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {C1965F10-18EF-43D7-AA04-9AFE655BBB72} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {DBCC24DB-5284-43AC-B8B5-E1DCD5DC49AA} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {DD1011A4-8958-472A-8771-C58A3E23BBB6} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {F9117665-0257-49FA-90FE-D867C279979B} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state on
Hosts:
EmptyTemp:

  • Save this as fixlist.txt, in the same location as FRST.exe on your desktop.
    FRSTfix.JPG
  • Run FRST by right clicking on it and selecting Run as Administrator and press Fix
  • On completion a log (fixlog.txt) will be generated.
  • Please select all text in this fix, copy (CTRL + C) and then Paste (CTRL + V) in your next reply.


    Step3 - adwcleaner

    Download AdwCleaner from here to the Desktop
  • Close all open windows and browsers
  • Double click the Adwcleaner icon to execute the program
  • When the Tool opens for the first time accept the Terms of use
    adwcleaner_zpslhu4ltda.jpg
  • Click the Scan button and wait for the program to finish.
  • Click on options tick -
    Reset proxy settings
    Reset winsock settings
    Reset TCP/IP settings
    Reset IPSec settings
    Reset Internet Explorer policies
    Reset Chrome policies
  • When finished, please click Cleaning button.
  • Upon completion, click Logfile. A log (AdwCleaner[C*].txt) will open.
  • Please copy and paste this in your next reply.


    Things for your next post:
  • fixlog.txt
  • AdwCleaner[C*].txt
  • How is the computer running?

  • 0

#4
Bruce1270

Bruce1270

    Trusted Helper

  • Malware Removal
  • 1,714 posts

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP