Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

PC recently and suddenly became very sluggish and unresonsive across a


  • This topic is locked This topic is locked

#1
Lyanheart

Lyanheart

    Member

  • Member
  • PipPipPip
  • 136 posts

I first noticed this on Monday, 2 days ago. Very sluggish response from PC no matter what I am doing, and applications frequently show the (not responding) message at the top of the window. Website response times using Chrome and IE are both much slower than normal. Even making this post was a very slow process that froze up a couple of times. FRST logs attached, and running that even took a lot longer than it has in the past when I have run it for other issues. Rebooting the PC seems to help, but the probem comes back. Sometimes it appears that I am experiencing really high RAM usage...?

 

Thanks in advance! This forum has saved me some so many problems over the years and it is still the first place I turn.

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-05-2017
Ran by Ryan2011 (administrator) on RYAN2011-PC (10-05-2017 10:39:23)
Running from C:\Users\Ryan2011\Desktop\Malware
Loaded Profiles: Ryan2011 (Available Profiles: Ryan2011)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
( ) C:\Windows\System32\dlbkcoms.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\agent.exe
(Microsoft Corporation) C:\Windows\System32\sdclt.exe
(Google Inc.) C:\Users\Ryan2011\AppData\Local\Google\Update\GoogleUpdate.exe
(Google Inc.) C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8306208 2009-10-20] (Realtek Semiconductor)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [Microsoft Default Manager] => C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [35760 2010-09-23] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46952 2011-08-02] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [30568 2011-08-02] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2013-01-30] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4522496 2012-12-27] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [2009088 2013-01-18] (Brother Industries, Ltd.)
Winlogon\Notify\GoToAssist: 
Winlogon\Notify\igfxcui: 
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [5142664 2014-12-21] (Plex, Inc.)
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\Run: [Google Update] => C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.)
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\Run: [Dropbox Update] => C:\Users\Ryan2011\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-07] (Dropbox, Inc.)
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\Run: [Yahoo Messenger Updater] => C:\Users\Ryan2011\AppData\Roaming\Yahoo Messenger\YMUpdater\YMUpdater.exe [115144 2016-08-22] (Yahoo!, Inc.)
HKU\S-1-5-18\...\Run: [] => [X]
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-01] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk [2016-06-17]
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\Ryan2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2017-05-02]
ShortcutTarget: Dropbox.lnk -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{288D171A-CEE6-471A-B1B8-884749FB721A}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{2DBCD195-5512-4C7A-8C99-29D6593BD0FF}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com/
SearchScopes: HKLM -> {DC718571-D9D1-419F-8C55-D9E6BD5837E5} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {B0774E76-A7A8-4B69-B75F-965BB88F7716} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll => No File
DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: HKLM-x32 {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} 
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
 
FireFox:
========
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: (Default Manager) - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-02-21] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-09] ()
FF Plugin: @java.com/DTPlugin -> C:\Program Files\Java\jre6\bin\npDeployJava1.dll [No File]
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [No File]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-09] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin HKU\S-1-5-21-1237553287-1429794397-2156527687-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1237553287-1429794397-2156527687-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1237553287-1429794397-2156527687-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Ryan2011\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-01-14] (Unity Technologies ApS)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Ryan2011\AppData\Local\Google\Chrome\User Data\Default [2017-05-10]
CHR Extension: (Flip this) - C:\Users\Ryan2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\donljlliiecjcagcenoeohjmabfegkph [2015-07-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ryan2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Chrome Media Router) - C:\Users\Ryan2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-04]
StartMenuInternet: Google Chrome - C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2012-10-26] (Brother Industries, Ltd.) [File not signed]
R2 dlbk_device; C:\Windows\system32\dlbkcoms.exe [567024 2007-06-25] ( )
S4 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [145256 2011-08-02] (Nuance Communications, Inc.)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
S3 CSRBC; C:\Windows\System32\Drivers\csrbc.sys [38400 2011-05-18] (CSR plc.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-05-10] ()
S3 gtfilter; C:\Windows\System32\DRIVERS\gtfilter.sys [18272 2012-01-03] (Fructel AB)
S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-05-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [251840 2017-05-10] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82208 2017-05-10] (Malwarebytes)
R3 RTL8023x64; C:\Windows\System32\DRIVERS\Rtnic64.sys [51712 2009-06-10] (Realtek Semiconductor Corporation                           )
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-10 09:46 - 2017-05-10 09:47 - 16588395 _____ C:\Users\Ryan2011\Downloads\CastawaysQuickStartGuideToRobinsonCrusoeV17.pdf
2017-05-10 09:35 - 2017-05-10 09:37 - 17980570 _____ C:\Users\Ryan2011\Downloads\Scenario Treasure Island.zip
2017-05-10 08:15 - 2017-05-10 08:15 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{1B65113B-AB9D-4A16-970D-BD5FA021C01D}
2017-05-09 16:40 - 2017-05-09 16:40 - 00657255 _____ C:\Users\Ryan2011\Downloads\TIME_Stories_Plain_and_Simple_Guide.pdf
2017-05-09 15:22 - 2017-05-09 15:22 - 03151051 _____ C:\Users\Ryan2011\Downloads\Goldland_Rules_R2.pdf
2017-05-09 14:23 - 2017-05-09 14:23 - 02194099 _____ C:\Users\Ryan2011\Downloads\RC_cards_mini_Euro_small.pdf
2017-05-09 14:20 - 2017-05-09 14:20 - 03514827 _____ C:\Users\Ryan2011\Downloads\RC_cards_mini_Euro_small_v2s.pdf
2017-05-09 14:16 - 2017-05-09 14:16 - 01552272 _____ C:\Users\Ryan2011\Downloads\RC_discovery_cards_v1_2.zip
2017-05-09 10:02 - 2017-05-09 10:04 - 12814840 _____ C:\Users\Ryan2011\Downloads\Regex'_Horizontal_Tuckbox_set_for_Sleeved_Robinson_Crusoe_Cards.pdf
2017-05-09 09:59 - 2017-05-09 09:59 - 10411873 _____ C:\Users\Ryan2011\Downloads\Regex_Box_for_Robinson_Crusoe_Hex_Tiles.pdf
2017-05-09 09:55 - 2017-05-09 09:55 - 04180861 _____ C:\Users\Ryan2011\Downloads\Robinson_crusoe_box.pdf
2017-05-09 09:53 - 2017-05-09 09:53 - 05278274 _____ C:\Users\Ryan2011\Downloads\RC_Cortes_Scenario_v2.43.pdf
2017-05-09 09:52 - 2017-05-09 09:52 - 03063130 _____ C:\Users\Ryan2011\Downloads\Logbook_ScoreSheet.pdf
2017-05-09 09:49 - 2017-05-09 09:49 - 01434327 _____ C:\Users\Ryan2011\Downloads\RobinsonCrusoe_v1.3.pdf
2017-05-09 09:48 - 2017-05-09 09:48 - 11531432 _____ C:\Users\Ryan2011\Downloads\robinson-crusoe-2-pager.pdf
2017-05-09 09:47 - 2017-05-09 09:47 - 01111237 _____ C:\Users\Ryan2011\Downloads\The_mutineers_of_the_Bounty_(Version_1.1).pdf
2017-05-09 09:41 - 2017-05-09 09:41 - 20465055 _____ C:\Users\Ryan2011\Downloads\robinson_crusoe_rulebook_EN_net.pdf
2017-05-09 09:38 - 2017-05-09 09:38 - 01617227 _____ C:\Users\Ryan2011\Downloads\rc_rulebook_letter_pf.pdf
2017-05-09 08:08 - 2017-05-09 08:08 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{24BFDA4F-F51B-48B9-976D-06A970989680}
2017-05-08 11:42 - 2017-05-08 11:42 - 00234528 _____ C:\Users\Ryan2011\Downloads\770544_Document_114248.pdf
2017-05-08 10:45 - 2017-05-08 10:45 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{687EDABF-6152-4750-A07C-F94A767AD90C}
2017-05-08 08:31 - 2017-05-08 08:31 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{175ADA9C-E541-4268-BFB4-461B1C60476B}
2017-05-05 11:03 - 2017-05-05 11:03 - 00117293 _____ C:\Users\Ryan2011\Downloads\Imperial_Assault_Tile_Chart.pdf
2017-05-05 11:00 - 2017-05-05 11:00 - 00909023 _____ C:\Users\Ryan2011\Downloads\SWImperialAssault_v1.4.pdf
2017-05-05 10:10 - 2017-05-05 10:12 - 00313023 _____ C:\Windows\system32\mbarwind-04.arw
2017-05-05 08:36 - 2017-05-05 08:36 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{02C05C4E-8EF4-4E51-A9B0-DBE1142E350B}
2017-05-04 07:55 - 2017-05-04 07:55 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{C05779AA-3437-4BDB-A742-95A119C840C0}
2017-05-03 08:02 - 2017-05-03 08:02 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{AA734D3F-1B68-4E44-A21D-8453F5BEC264}
2017-05-02 14:36 - 2017-05-02 14:36 - 00000000 ____D C:\Users\Ryan2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-05-02 10:47 - 2017-05-02 10:47 - 01160143 _____ C:\Users\Ryan2011\Downloads\ArkHorror_base_teachingaid_v2.pdf
2017-05-02 10:44 - 2017-05-02 10:45 - 05026144 _____ C:\Users\Ryan2011\Downloads\misc_cards.zip
2017-05-02 08:12 - 2017-05-02 08:12 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{1D3038EF-AD75-47A0-AAC4-CA5EA52C3102}
2017-05-01 15:07 - 2017-05-01 15:07 - 01167562 _____ C:\Users\Ryan2011\Downloads\5_boxes.pdf
2017-05-01 15:04 - 2017-05-01 15:04 - 02432700 _____ C:\Users\Ryan2011\Downloads\Agricola_Tuckboxes.pdf
2017-05-01 15:02 - 2017-05-01 15:03 - 04337135 _____ C:\Users\Ryan2011\Downloads\tuckboxes_agricola_v3.0.pdf
2017-05-01 08:23 - 2017-05-01 08:23 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{09A9878A-6080-4F5E-8305-88A177CBC5C1}
2017-04-28 15:08 - 2017-04-28 15:08 - 00020665 _____ C:\Users\Ryan2011\Downloads\Residential_4-28-2017_1580.pdf
2017-04-28 09:36 - 2017-04-28 09:36 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{9522377A-0C93-442C-827C-AE76A268C955}
2017-04-28 09:03 - 2017-04-28 09:04 - 00042354 _____ C:\Users\Ryan2011\Downloads\114-5212472-2431454.pdf
2017-04-27 10:11 - 2017-04-27 10:11 - 00825029 _____ C:\Users\Ryan2011\Downloads\Custom_Investigator.pdf
2017-04-27 09:57 - 2017-04-27 09:58 - 00773023 _____ C:\Users\Ryan2011\Downloads\MansionsofMadness2ndEd_v1.pdf
2017-04-27 08:41 - 2017-04-27 08:41 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{74BD50E1-065A-4357-BA2F-DFE327FE68CA}
2017-04-26 08:13 - 2017-04-26 08:13 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{949955DC-D506-469F-B61B-7105A25AC4DA}
2017-04-26 07:55 - 2017-04-26 07:55 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{6684DF2B-F857-4055-93C5-6AC4D4A4620F}
2017-04-25 08:25 - 2017-04-25 08:25 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{BAF34DD1-26FD-4074-9065-6A01218957D3}
2017-04-24 16:48 - 2017-04-24 16:48 - 00126927 _____ C:\Users\Ryan2011\Downloads\Super-charged_solo_coop_variant_V1.pdf
2017-04-24 16:46 - 2017-04-24 16:46 - 01856006 _____ C:\Users\Ryan2011\Downloads\Return_of_the_Heroes_v12.pdf
2017-04-24 16:42 - 2017-04-24 16:42 - 00157809 _____ C:\Users\Ryan2011\Downloads\Return_Of_The_Heroes_Play_Aid_by_Liumas_v1.1.zip
2017-04-24 09:06 - 2017-04-24 09:06 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{86203DC6-6757-4066-9722-6F38729A6914}
2017-04-21 16:11 - 2017-03-27 14:13 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-04-21 16:11 - 2017-03-27 13:28 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-04-21 16:11 - 2017-03-25 15:39 - 20284416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-04-21 16:11 - 2017-03-25 15:07 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-04-21 16:11 - 2017-03-25 15:06 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-04-21 16:11 - 2017-03-25 14:55 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-04-21 16:11 - 2017-03-25 14:52 - 02289152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-04-21 16:11 - 2017-03-25 14:51 - 01313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-04-21 16:11 - 2017-03-25 14:48 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-04-21 16:11 - 2017-03-25 14:47 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-04-21 16:11 - 2017-03-25 14:47 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-04-21 16:11 - 2017-03-25 14:47 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-04-21 16:11 - 2017-03-25 14:46 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-04-21 16:11 - 2017-03-25 14:46 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-04-21 16:11 - 2017-03-25 14:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-04-21 16:11 - 2017-03-25 14:46 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-04-21 16:11 - 2017-03-25 14:46 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-04-21 16:11 - 2017-03-25 14:46 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-04-21 16:11 - 2017-03-25 14:46 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-21 16:11 - 2017-03-25 14:46 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-04-21 16:11 - 2017-03-25 14:45 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-04-21 16:11 - 2017-03-25 14:45 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-04-21 16:11 - 2017-03-25 14:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-04-21 16:11 - 2017-03-25 14:45 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-04-21 16:11 - 2017-03-25 14:45 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-04-21 16:11 - 2017-03-25 14:45 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-04-21 16:11 - 2017-03-25 14:45 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-04-21 16:11 - 2017-03-25 14:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-04-21 16:11 - 2017-03-25 14:44 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-04-21 16:11 - 2017-03-25 14:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-04-21 16:11 - 2017-03-25 14:35 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-04-21 16:11 - 2017-03-25 14:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-04-21 16:11 - 2017-03-25 14:14 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-04-21 16:11 - 2017-03-25 14:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-04-21 16:11 - 2017-03-25 14:13 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-04-21 16:11 - 2017-03-25 14:13 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-04-21 16:11 - 2017-03-25 14:10 - 02898432 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-04-21 16:11 - 2017-03-25 14:04 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-04-21 16:11 - 2017-03-25 14:02 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-04-21 16:11 - 2017-03-25 13:57 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-04-21 16:11 - 2017-03-25 13:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-04-21 16:11 - 2017-03-25 13:56 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-04-21 16:11 - 2017-03-25 13:56 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-04-21 16:11 - 2017-03-25 13:56 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-04-21 16:11 - 2017-03-25 13:52 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-04-21 16:11 - 2017-03-25 13:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-04-21 16:11 - 2017-03-25 13:41 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-04-21 16:11 - 2017-03-25 13:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-04-21 16:11 - 2017-03-25 13:30 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-04-21 16:11 - 2017-03-25 13:29 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-04-21 16:11 - 2017-03-25 13:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-04-21 16:11 - 2017-03-25 13:23 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-04-21 16:11 - 2017-03-25 13:20 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-04-21 16:11 - 2017-03-25 13:19 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-04-21 16:11 - 2017-03-25 13:17 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-04-21 16:11 - 2017-03-25 13:06 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-04-21 16:11 - 2017-03-25 13:04 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-04-21 16:11 - 2017-03-25 13:00 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-04-21 16:11 - 2017-03-25 12:59 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-04-21 16:11 - 2017-03-25 12:57 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-04-21 16:11 - 2017-03-25 12:57 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-04-21 16:11 - 2017-03-25 12:28 - 15259136 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-04-21 16:11 - 2017-03-25 12:27 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-04-21 16:11 - 2017-03-25 12:24 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-04-21 16:11 - 2017-03-25 12:10 - 01546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-04-21 16:11 - 2017-03-25 12:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-04-21 16:11 - 2017-03-24 18:50 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-04-21 16:11 - 2017-03-24 18:42 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-04-21 16:11 - 2017-03-22 11:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-04-21 16:11 - 2017-03-22 11:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-04-21 16:11 - 2017-03-22 11:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-04-21 16:11 - 2017-03-22 11:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-04-21 16:11 - 2017-03-22 11:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-21 16:11 - 2017-03-22 11:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-21 16:11 - 2017-03-22 11:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-21 16:11 - 2017-03-22 11:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-04-21 16:11 - 2017-03-22 11:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-04-21 16:11 - 2017-03-22 11:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-04-21 16:11 - 2017-03-22 11:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-04-21 16:11 - 2017-03-22 11:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-04-21 16:11 - 2017-03-22 11:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-21 16:11 - 2017-03-22 11:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-21 16:11 - 2017-03-22 11:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-04-21 16:11 - 2017-03-22 11:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-21 16:11 - 2017-03-14 11:34 - 00986344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-04-21 16:11 - 2017-03-14 11:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-04-21 16:11 - 2017-03-14 11:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-04-21 16:11 - 2017-03-10 12:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-04-21 16:11 - 2017-03-10 12:32 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-04-21 16:11 - 2017-03-10 12:32 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-04-21 16:11 - 2017-03-10 12:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-04-21 16:11 - 2017-03-10 12:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-04-21 16:11 - 2017-03-10 12:31 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-04-21 16:11 - 2017-03-10 12:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-04-21 16:11 - 2017-03-10 12:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-04-21 16:11 - 2017-03-10 12:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-21 16:11 - 2017-03-10 12:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-04-21 16:11 - 2017-03-10 12:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2017-04-21 16:11 - 2017-03-10 12:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-04-21 16:11 - 2017-03-10 12:19 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-04-21 16:11 - 2017-03-10 12:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-04-21 16:11 - 2017-03-10 12:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-04-21 16:11 - 2017-03-10 12:00 - 03219968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-04-21 16:11 - 2017-03-10 11:57 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-04-21 16:11 - 2017-03-10 11:55 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-04-21 16:11 - 2017-03-10 11:55 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-04-21 16:11 - 2017-03-10 11:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-21 16:11 - 2017-03-09 12:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-04-21 16:11 - 2017-03-09 12:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-04-21 16:11 - 2017-03-08 16:20 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-04-21 16:11 - 2017-03-08 16:10 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-04-21 16:11 - 2017-03-08 00:37 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-04-21 16:11 - 2017-03-08 00:36 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-04-21 16:11 - 2017-03-08 00:36 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-04-21 16:11 - 2017-03-08 00:36 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-04-21 16:11 - 2017-03-08 00:36 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-04-21 16:11 - 2017-03-08 00:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 02064384 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:26 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-04-21 16:11 - 2017-03-08 00:26 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-04-21 16:11 - 2017-03-08 00:24 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 01416192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-04-21 16:11 - 2017-03-08 00:22 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-21 16:11 - 2017-03-08 00:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-04-21 16:11 - 2017-03-08 00:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-04-21 16:11 - 2017-03-08 00:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-04-21 16:11 - 2017-03-08 00:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-04-21 16:11 - 2017-03-08 00:00 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-04-21 16:11 - 2017-03-07 23:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-04-21 16:11 - 2017-03-07 23:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-04-21 16:11 - 2017-03-07 23:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-04-21 16:11 - 2017-03-07 23:56 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-04-21 16:11 - 2017-03-07 23:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-04-21 16:11 - 2017-03-07 23:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-04-21 16:11 - 2017-03-07 23:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-04-21 16:11 - 2017-03-07 23:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-04-21 16:11 - 2017-03-07 23:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-04-21 16:11 - 2017-03-07 23:54 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-04-21 16:11 - 2017-03-07 23:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-04-21 16:11 - 2017-03-07 23:53 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-04-21 16:11 - 2017-03-07 23:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-21 16:11 - 2017-03-07 23:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-21 16:11 - 2017-03-07 23:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-21 16:11 - 2017-03-07 23:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-21 16:11 - 2017-03-07 12:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-04-21 16:11 - 2017-03-07 12:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-21 16:11 - 2017-03-07 10:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-04-21 16:11 - 2017-03-03 21:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-04-21 16:11 - 2017-03-03 21:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-04-21 16:11 - 2017-03-03 21:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-21 16:11 - 2017-03-03 21:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-21 16:11 - 2017-02-14 12:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-04-21 16:11 - 2017-02-14 12:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-04-21 16:11 - 2017-02-09 12:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-04-21 16:11 - 2017-02-09 12:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-04-21 16:11 - 2017-02-09 12:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-21 16:11 - 2017-01-18 11:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-21 16:11 - 2016-03-23 18:40 - 03181568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-04-21 16:11 - 2016-03-23 18:40 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2017-04-21 10:03 - 2017-04-21 10:03 - 00570675 _____ C:\Users\Ryan2011\Downloads\Enemy_In_Sight_Reference_by_Liumas_2008-08 (1).pdf
2017-04-21 10:02 - 2017-04-21 10:02 - 00570675 _____ C:\Users\Ryan2011\Downloads\Enemy_In_Sight_Reference_by_Liumas_2008-08.pdf
2017-04-21 07:59 - 2017-04-21 07:59 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{E30707B4-6A62-4992-9E26-A56C2425E91C}
2017-04-20 08:21 - 2017-04-20 08:21 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{FFEAA78A-637C-4FC6-939A-DAFD02883856}
2017-04-19 10:08 - 2017-04-19 10:08 - 00090140 _____ C:\Users\Ryan2011\Downloads\CivilizationRedesignHowTo.pdf
2017-04-19 09:19 - 2017-04-19 09:19 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{6B939AED-B134-4E79-A60E-F4D8BE4D48B4}
2017-04-19 08:44 - 2017-04-19 08:44 - 00088036 _____ C:\Users\Ryan2011\Downloads\tuckbox_civilization_civ-cards.pdf
2017-04-19 08:40 - 2017-04-19 08:40 - 00069672 _____ C:\Users\Ryan2011\Downloads\tuckbox_civilization_trade-cards.pdf
2017-04-19 08:35 - 2017-04-19 08:35 - 00021118 _____ C:\Users\Ryan2011\Downloads\Civilization_-_help_sheet.pdf
2017-04-19 08:34 - 2017-04-19 08:34 - 00232595 _____ C:\Users\Ryan2011\Downloads\Civilization-conciserules-Gibson1988v1.0d(beta).pdf
2017-04-19 08:33 - 2017-04-19 08:33 - 00157621 _____ C:\Users\Ryan2011\Downloads\Civilization-conciserules-Gibson1988v1.0e(beta) (1).pdf
2017-04-18 14:26 - 2017-04-18 14:26 - 00055865 _____ C:\Users\Ryan2011\Downloads\Magic_Realm_Labels_-_Avery_5267.pdf
2017-04-18 14:24 - 2017-04-18 14:24 - 00351520 _____ C:\Users\Ryan2011\Downloads\phsheet_rev.pdf
2017-04-18 09:47 - 2017-04-18 09:47 - 01054903 _____ C:\Users\Ryan2011\Downloads\MR_Redesigned_Character_Cards_Corrections.zip
2017-04-18 09:46 - 2017-04-18 09:46 - 00949660 _____ C:\Users\Ryan2011\Downloads\Character_Record.pdf
2017-04-18 09:45 - 2017-04-18 09:45 - 00379913 _____ C:\Users\Ryan2011\Downloads\transform.pdf
2017-04-18 09:42 - 2017-04-18 09:42 - 00053134 _____ C:\Users\Ryan2011\Downloads\phsheet.pdf
2017-04-18 09:41 - 2017-04-18 09:41 - 07011586 _____ C:\Users\Ryan2011\Downloads\countersheets.zip
2017-04-18 09:41 - 2017-04-18 09:41 - 00021929 _____ C:\Users\Ryan2011\Downloads\phsheet2.pdf
2017-04-18 09:06 - 2017-04-18 09:06 - 00999286 _____ C:\Users\Ryan2011\Downloads\MRIPE.pdf
2017-04-18 08:50 - 2017-04-18 08:50 - 00352556 _____ C:\Users\Ryan2011\Downloads\MonstersHowToKillThem.pdf
2017-04-18 08:48 - 2017-04-18 08:48 - 00039671 _____ C:\Users\Ryan2011\Downloads\LeastMR8.pdf
2017-04-18 08:44 - 2017-04-18 08:44 - 08752907 _____ C:\Users\Ryan2011\Downloads\MR-31-Deluxe_beta.pdf
2017-04-18 08:40 - 2017-04-18 08:40 - 00856590 _____ C:\Users\Ryan2011\Downloads\MagicRealmCharacterStrategies1.pdf
2017-04-18 08:38 - 2017-04-18 08:38 - 01358420 _____ C:\Users\Ryan2011\Downloads\magic_realm_setup_card_sections.pdf
2017-04-18 08:37 - 2017-04-18 08:37 - 00102014 _____ C:\Users\Ryan2011\Downloads\MR_Game_Record.pdf
2017-04-18 08:36 - 2017-04-18 08:36 - 00021331 _____ C:\Users\Ryan2011\Downloads\MR-Player_Aid.pdf
2017-04-18 08:33 - 2017-04-18 08:33 - 00982516 _____ C:\Users\Ryan2011\Downloads\book_of_quests_3ed_v1.pdf
2017-04-18 08:29 - 2017-04-18 08:29 - 00159618 _____ C:\Users\Ryan2011\Downloads\Redesgined_Character_Chits_20161017.pdf
2017-04-18 07:58 - 2017-04-18 07:58 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{A9536B23-AB51-4504-8EE4-BF99D3CB8E25}
2017-04-17 09:22 - 2017-04-17 09:22 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{BE55A82C-4C1E-46B4-8C37-7CE74C67C77D}
2017-04-17 08:43 - 2017-04-17 08:43 - 00109536 _____ C:\Users\Ryan2011\Downloads\[email protected]
2017-04-17 08:36 - 2017-04-17 08:36 - 00146803 _____ C:\Users\Ryan2011\Downloads\Farkle_Score_Pad.pdf
2017-04-14 15:33 - 2017-04-14 15:33 - 00309723 _____ C:\Users\Ryan2011\Downloads\MR_Tables_mini.pdf
2017-04-14 15:17 - 2017-04-14 15:17 - 01771689 _____ C:\Users\Ryan2011\Downloads\Magic_Realm_3.1_Complete_(touched-up).pdf
2017-04-14 15:05 - 2017-04-14 15:06 - 09290736 _____ C:\Users\Ryan2011\Downloads\book_of_learning_v1.pdf
2017-04-14 14:54 - 2017-04-14 14:54 - 01807922 _____ C:\Users\Ryan2011\Downloads\MR-31-Complete.pdf
2017-04-14 11:02 - 2017-04-14 11:02 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{2DA14968-0A71-4BA3-A13A-F28953BD9585}
2017-04-14 11:01 - 2017-04-14 11:01 - 00866584 _____ C:\Users\Ryan2011\Downloads\MagicRealmLight30-2ndEditionFillablev2.pdf
2017-04-14 10:58 - 2017-04-14 10:58 - 01378795 _____ C:\Users\Ryan2011\Downloads\MagicRealmLight30PortraitRules21.zip
2017-04-14 10:39 - 2017-04-14 10:39 - 00030531 _____ C:\Users\Ryan2011\Downloads\EnemyInSight_QuickRefENG.pdf
2017-04-14 09:16 - 2017-04-14 09:16 - 00344394 _____ C:\Users\Ryan2011\Downloads\GARDENSOFMARS_EN.pdf
2017-04-13 14:29 - 2017-04-13 14:29 - 00040345 _____ C:\Users\Ryan2011\Downloads\221B_solution_checklist-080818-1.pdf
2017-04-13 14:24 - 2017-04-13 14:24 - 00092985 _____ C:\Users\Ryan2011\Downloads\221b_Movement_Variant.pdf
2017-04-13 14:23 - 2017-04-13 14:23 - 00173133 _____ C:\Users\Ryan2011\Downloads\221B_Clues.pdf
2017-04-13 14:21 - 2017-04-13 14:21 - 00089448 _____ C:\Users\Ryan2011\Downloads\221B_hansom_variant-080818-v1.pdf
2017-04-13 08:23 - 2017-04-13 08:23 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{13EB0C4B-FCFC-4B0E-AA4E-F25FF1135E84}
2017-04-12 09:57 - 2017-04-12 09:57 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{32E42171-0814-4A8F-A423-F4D1BBEBC9D2}
2017-04-11 11:32 - 2017-04-11 11:32 - 00338169 _____ C:\Users\Ryan2011\Downloads\Santorini_Gods_Reference_1.2 (1).pdf
2017-04-11 11:28 - 2017-04-11 11:29 - 00880289 _____ C:\Users\Ryan2011\Downloads\Dragonmaster_Tuckbox (1).pdf
2017-04-11 11:28 - 2017-04-11 11:28 - 01101471 _____ C:\Users\Ryan2011\Downloads\Dragonmaster_Tuckbox.pdf
2017-04-11 08:02 - 2017-04-11 08:02 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{37FF8EF3-9C6A-4A6B-BCA5-ED557AE742AE}
2017-04-10 15:28 - 2017-04-10 16:56 - 06579383 _____ C:\Windows\system32\mbarwind-03.arw
2017-04-10 14:50 - 2017-04-10 14:50 - 03013185 _____ C:\Users\Ryan2011\Downloads\Advanced_Outdoor_Survival.pdf
2017-04-10 14:48 - 2017-04-10 14:48 - 00093742 _____ C:\Users\Ryan2011\Downloads\DBCooper.pdf
2017-04-10 14:45 - 2017-04-10 14:45 - 00129299 _____ C:\Users\Ryan2011\Downloads\Game_Scenario_-_Outdoor_Survival_-_Off-Road_Race_-_With_Tracking_Charts_-_Update_1.pdf
2017-04-10 11:02 - 2017-04-10 11:02 - 00052882 _____ C:\Users\Ryan2011\Downloads\Civ_Cheatsheet.pdf
2017-04-10 10:55 - 2017-04-10 10:55 - 01707133 _____ C:\Users\Ryan2011\Downloads\civ.zip
2017-04-10 10:54 - 2017-04-10 10:54 - 00157621 _____ C:\Users\Ryan2011\Downloads\Civilization-conciserules-Gibson1988v1.0e(beta).pdf
2017-04-10 07:50 - 2017-04-10 07:50 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\{94B19722-50C9-413E-AD22-04C9BFB6FF2E}
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-10 10:39 - 2015-01-12 09:10 - 00000000 ____D C:\Users\Ryan2011\Desktop\Malware
2017-05-10 10:39 - 2013-10-25 11:19 - 00000000 ____D C:\FRST
2017-05-10 10:14 - 2016-08-22 07:50 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\yahoomessenger
2017-05-10 10:10 - 2012-07-17 09:05 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\Samsung
2017-05-10 10:10 - 2011-04-01 11:42 - 00000000 ____D C:\ProgramData\Samsung
2017-05-10 10:09 - 2015-02-12 16:18 - 00007891 _____ C:\Windows\BRRBCOM.INI
2017-05-10 10:09 - 2011-04-26 10:18 - 00000000 ____D C:\Temp
2017-05-10 09:43 - 2017-01-27 15:08 - 00082208 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-05-10 09:21 - 2017-01-27 15:08 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-05-10 09:21 - 2015-01-12 09:53 - 00251840 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-05-10 09:20 - 2017-01-27 15:08 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-05-10 08:58 - 2011-01-31 17:14 - 00003950 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{E2EFC854-A19B-421C-8245-B34FDE8E3A62}
2017-05-10 07:44 - 2017-01-27 15:08 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-05-10 03:50 - 2009-07-14 00:45 - 00022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-10 03:50 - 2009-07-14 00:45 - 00022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-09 17:08 - 2009-07-14 01:13 - 00780750 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-09 17:08 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2017-05-09 17:04 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-09 10:30 - 2011-02-01 11:16 - 00000000 ____D C:\Leonard Ins
2017-05-09 09:47 - 2012-03-30 07:49 - 00803320 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-05-09 09:47 - 2012-03-30 07:49 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-05-09 09:47 - 2011-05-18 07:51 - 00144888 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-05-09 09:47 - 2011-04-05 16:35 - 00000000 ____D C:\Windows\system32\Macromed
2017-05-09 09:47 - 2010-09-10 03:48 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-05-02 14:36 - 2012-02-23 13:50 - 00000000 ___RD C:\Users\Ryan2011\Dropbox
2017-05-02 14:36 - 2012-02-23 13:44 - 00000000 ____D C:\Users\Ryan2011\AppData\Roaming\Dropbox
2017-04-28 16:55 - 2011-04-25 09:55 - 00000000 ____D C:\Program Files (x86)\Steam
2017-04-28 09:08 - 2011-05-03 15:10 - 00003514 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1237553287-1429794397-2156527687-1000UA
2017-04-28 09:08 - 2011-05-03 15:10 - 00003242 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1237553287-1429794397-2156527687-1000Core
2017-04-24 17:19 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2017-04-24 08:26 - 2013-03-14 16:59 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-24 08:26 - 2009-07-14 00:45 - 00351192 _____ C:\Windows\system32\FNTCACHE.DAT
2017-04-24 08:25 - 2013-03-14 16:59 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-21 16:24 - 2013-03-14 17:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-04-21 16:21 - 2013-08-14 12:02 - 00000000 ____D C:\Windows\system32\MRT
2017-04-21 16:19 - 2011-02-01 15:42 - 148601744 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-04-21 16:16 - 2011-01-31 17:37 - 00748458 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-04-17 08:45 - 2011-01-31 13:36 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\VirtualStore
2017-04-14 15:25 - 2011-02-02 12:18 - 00000000 ____D C:\Users\Ryan2011\AppData\Local\CutePDF Writer
2017-04-11 11:32 - 2015-04-16 09:19 - 00000000 ____D C:\Users\Ryan2011\Board Game Materials
 
==================== Files in the root of some directories =======
 
2011-02-10 09:36 - 2015-02-12 15:54 - 0043247 _____ () C:\ProgramData\hpzinstall.log
 
Some files in TEMP:
====================
2017-05-10 10:15 - 2008-05-07 14:55 - 0153088 _____ () C:\Users\Ryan2011\AppData\Local\Temp\GLB1A2B.EXE
2017-05-10 10:05 - 2012-06-26 16:02 - 0135168 _____ (Musiccity Co.Ltd.) C:\Users\Ryan2011\AppData\Local\Temp\muzaf1.dll
2017-05-10 10:05 - 2012-06-26 16:02 - 0491520 _____ (Musiccity Co.Ltd.) C:\Users\Ryan2011\AppData\Local\Temp\muzapp.dll
2017-05-10 10:05 - 2012-06-26 16:02 - 0172032 _____ (Musiccity Co.Ltd.) C:\Users\Ryan2011\AppData\Local\Temp\muzapp.exe
2017-05-10 10:05 - 2012-06-26 16:02 - 0200704 _____ ( © MusicCity) C:\Users\Ryan2011\AppData\Local\Temp\muzwmts.dll
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-05-03 00:27
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-05-2017
Ran by Ryan2011 (10-05-2017 10:47:43)
Running from C:\Users\Ryan2011\Desktop\Malware
Windows 7 Home Premium Service Pack 1 (X64) (2011-01-31 17:32:41)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1237553287-1429794397-2156527687-500 - Administrator - Disabled)
Guest (S-1-5-21-1237553287-1429794397-2156527687-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-1237553287-1429794397-2156527687-1008 - Limited - Enabled)
Ryan2011 (S-1-5-21-1237553287-1429794397-2156527687-1000 - Administrator - Enabled) => C:\Users\Ryan2011
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.6.0.5970 - Adobe Systems Incorporated)
Adobe Flash Player 25 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Adobe Photoshop 7.0 (HKLM-x32\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.)
Adobe Reader 9.4.0 (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-A94000000001}) (Version: 9.4.0 - Adobe Systems Incorporated)
Amazon MP3 Downloader 1.0.15 (HKLM-x32\...\Amazon MP3 Downloader) (Version: 1.0.15 - Amazon Services LLC)
Amazon Music Importer (HKLM-x32\...\com.amazon.music.uploader) (Version: 2.0.1 - Amazon Services LLC)
Amazon Music Importer (x32 Version: 2.0.1 - Amazon Services LLC) Hidden
A-PDF Page Cut (HKLM-x32\...\A-PDF Page Cut_is1) (Version:  - A-PDF Solution)
Banished (HKLM-x32\...\Steam App 242920) (Version:  - Shining Rock Software LLC)
Bing Rewards Client Installer (x32 Version: 16.0.345.0 - Microsoft Corporation) Hidden
Brother MFL-Pro Suite MFC-J870DW (HKLM-x32\...\{7B4C83B6-17C1-4BFD-B86D-4D7AD4498CBB}) (Version: 1.0.3.0 - Brother Industries, Ltd.)
Carcassonne (HKLM-x32\...\{8033CA80-B44F-40F9-8D0A-957211442C19}) (Version: 1.0 - Deep Silver)
CCleaner (HKLM\...\CCleaner) (Version: 3.20 - Piriform)
Cole2k Media - Codec Pack (Advanced) 8.0.2 (HKLM-x32\...\Cole2k Media - Codec Pack) (Version: 8.0.2 - Cole2k Media)
Combined Community Codec Pack 2011-11-11 (HKLM-x32\...\Combined Community Codec Pack_is1) (Version: 2011.11.11.0 - CCCP Project)
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
CutePDF Writer 2.8 (HKLM\...\CutePDF Writer Installation) (Version:  - )
CutList Plus Express (HKLM-x32\...\{29C0946B-850E-4E9A-8DE3-AFB7109CC86C}) (Version: 1.1.3 - Bridgewood Design)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Desktop Icon Position Saver (64-bit) (HKLM-x32\...\dips64) (Version:  - )
Dominion (HKLM-x32\...\Dominion) (Version: 2.00.47.11 - MakingFun)
Dropbox (HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\Dropbox) (Version: 25.4.28 - Dropbox, Inc.)
Express Zip (HKLM-x32\...\ExpressZip) (Version: 2.17 - NCH Software)
FastImageResizer (remove only) (HKLM-x32\...\FastImageResizer) (Version:  - )
Free AVI Player (HKLM-x32\...\{7DED55EA-FB69-4101-AD5D-3D7F985E68A7}) (Version: 1.00.0000 - Media Freeware)
Gametel Configuration Tool 64-bit (HKLM\...\{7B83120F-92B3-45D7-A3A6-B034EF7AC5A9}) (Version: 1.2.1.0 - Fructel AB)
Google Chrome (HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.165 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.1.0.0 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Hoyle Casino (HKLM-x32\...\{3F99D180-34C3-4151-8C6C-86FC5D7BDFBD}) (Version: 1.0.0 - Encore)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
Informatik (HKLM-x32\...\Informatik_is1) (Version:  - )
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 9.6.0.1014 - Intel Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LibreOffice 4.3.7.2 (HKLM-x32\...\{8ED4A1FC-56CF-414C-A9AB-A37714AA9EA7}) (Version: 4.3.7.2 - The Document Foundation)
Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Mansions of Madness (HKLM\...\Steam App 478980) (Version:  - Fantasy Flight Games)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office Basic Edition 2003 (HKLM-x32\...\{91130409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual Basic PowerPacks 10.0 (HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\{4a461520-05cf-4df1-8957-844b4a811ff4}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Mp3tag v2.52 (HKLM-x32\...\Mp3tag) (Version: v2.52 - Florian Heidenreich)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Nuance PaperPort 12 (HKLM-x32\...\{869FCC6C-5669-4B0B-827E-2BBAACD88A87}) (Version: 12.1.0006 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
Palace of Chance (HKLM-x32\...\{f51a5449-9174-4e90-a0b2-bd67e0a9a87e}) (Version: 12.0.0 - RealTimeGaming Software)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 14.00.0000 - Nuance Communications, Inc.)
Plex Media Server (HKLM-x32\...\{7425d872-d65d-42c9-8c6d-7a8a529a4b50}) (Version: 0.9.1107 - Plex, Inc.)
Plex Media Server (x32 Version: 0.9.1107 - Plex, Inc.) Hidden
PosteRazor (HKLM-x32\...\PosteRazor_is1) (Version: 1.5.2 - Alessandro Portale)
Prism Video File Converter (HKLM-x32\...\Prism) (Version:  - NCH Software)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5963 - Realtek Semiconductor Corp.)
RollerCoaster Tycoon Deluxe (HKLM-x32\...\GOGPACKRTC_is1) (Version: 2.1.0.18 - GOG.com)
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.6.0 - SAMSUNG Electronics Co., Ltd.)
Scansoft PDF Professional (x32 Version:  - ) Hidden
SCARM 0.9.24 beta (HKLM-x32\...\{9BF3D390-A0AD-4733-AFC8-18E306B8E219}_is1) (Version: 0.9.24 - Milen Peev)
SketchUp 2013 (HKLM-x32\...\{72B622C9-AA10-47D7-A10C-377CF9BC8502}) (Version: 13.0.4124 - Trimble Navigation Limited)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Small World 2 (HKLM-x32\...\Steam App 235620) (Version:  - Days of Wonder)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Strange Eons 3745 (HKLM\...\0581-5195-2362-0248) (Version: 3745 - Christopher G. Jennings)
Talisman: Prologue (HKLM-x32\...\Steam App 258200) (Version:  - )
Ticket to Ride (HKLM-x32\...\Steam App 108200) (Version:  - Days of Wonder)
TQ Defiler.NET (HKLM-x32\...\{F4CB0C1E-A88F-46D7-AC9A-03B349A8D64F}) (Version: 1.3.7 - Soul's Software)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 3.9.26 - Tweaking.com)
Unity Web Player (HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Virtual Pool 3 DL (HKLM-x32\...\{7B4873B0-71FF-4BAA-8072-1DEE154C54E4}) (Version: 3.3.1.1 - Celeris)
Virtual Pool 3 Preview (HKLM-x32\...\{70E9BAF7-FCAF-465D-AF60-7C25F68D015C}) (Version: 3.2.3.9 - Celeris)
Virtual Pool 4 Demo (HKLM-x32\...\{76EA761E-E91A-4715-8511-12B7707E53BF}) (Version: 4.1.1.7 - Celeris)
Visual Pinball VPInstaller 1.0.3 (HKLM-x32\...\Visual Pinball) (Version: VPInstaller 1.0.3 - VPForums.org)
VLC media player 2.0.3 (HKLM-x32\...\VLC media player) (Version: 2.0.3 - VideoLAN)
Volume Activation Management Tool 2.0 (HKLM-x32\...\{EE010C18-9A1A-4F0E-B46E-884CA113232E}) (Version: 2.0.67.0 - Microsoft Corporation)
Windows Driver Package - Cambridge Silicon Radio Ltd. (CSRBC) USB  (02/03/2011 2.4.0.0) (HKLM\...\88C277C6E63CBDAF35A096E80A5B97A29A619D3A) (Version: 02/03/2011 2.4.0.0 - Cambridge Silicon Radio Ltd.)
Windows Driver Package - Fructel AB (usbser) Ports  (11/04/2011 1.0.0.0) (HKLM\...\CD721827CE36C3AEAB693B6DFF32C57AC19F2425) (Version: 11/04/2011 1.0.0.0 - Fructel AB)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
WinRAR 4.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\ChromeHTML: -> C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{799ff11c-a966-4c28-b7c4-b7d0ed801240}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{dd0949d3-a983-45b9-ad90-679bc855b724}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {11B44973-C307-410E-B060-BC52D00099B6} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1237553287-1429794397-2156527687-1000UA => C:\Users\Ryan2011\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-07] (Dropbox, Inc.)
Task: {64506389-48FD-4A6D-B4D1-13ED5817E66E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1237553287-1429794397-2156527687-1000UA => C:\Users\Ryan2011\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {757CC069-530F-4A09-95CD-861F832C0212} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1237553287-1429794397-2156527687-1000Core => C:\Users\Ryan2011\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {7F2810AD-1DC0-460F-BE58-B542A4D14CB3} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1237553287-1429794397-2156527687-1000Core => C:\Users\Ryan2011\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-07] (Dropbox, Inc.)
Task: {ABF70F24-614F-4F59-9ABD-CC61D6934431} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-11] (Tweaking.com)
Task: {CD96F50D-D4B2-4040-B732-45D70ECF4195} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-06-22] (Piriform Ltd)
Task: {E956ACFD-B423-47F8-8B1D-BFE24FF7D8EF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-09] (Adobe Systems Incorporated)
Task: {ECC21FC9-D70C-4F41-91D8-C96DFC8A8B50} - System32\Tasks\{730F5265-3543-43CD-B456-02F5030351B3} => C:\Program Files (x86)\Visual Pinball\VPinball_9_0_2.exe [2009-02-09] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2011-02-02 11:40 - 2009-11-05 08:40 - 00085504 _____ () C:\Windows\System32\cpwmon64.dll
2011-02-01 15:35 - 2007-02-28 09:53 - 00116224 _____ () C:\Windows\system32\spool\PRTPROCS\x64\dlbkpp6c.dll
2017-01-27 15:08 - 2017-02-24 07:23 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2017-01-27 15:08 - 2017-02-24 07:23 - 02264528 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00072840 _____ () C:\Program Files (x86)\Plex\Plex Media Server\zlib.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00196232 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libidn.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00838792 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libxml2.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00049800 _____ () C:\Program Files (x86)\Plex\Plex Media Server\soci_sqlite3-vc80-3_0.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00086664 _____ () C:\Program Files (x86)\Plex\Plex Media Server\soci_core-vc80-3_0.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 02092680 _____ () C:\Program Files (x86)\Plex\Plex Media Server\opencv_core249.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 01883272 _____ () C:\Program Files (x86)\Plex\Plex Media Server\opencv_imgproc249.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00502920 _____ () C:\Program Files (x86)\Plex\Plex Media Server\tag.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00044680 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_socket.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00027784 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ssl.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00018568 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_hashlib.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00034952 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\simplejson\_speedups.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00836232 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\etree.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00062600 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libexslt.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00166024 _____ () C:\Program Files (x86)\Plex\Plex Media Server\libxslt.dll
2014-12-21 23:31 - 2014-12-21 23:31 - 00192136 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\lxml\objectify.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00016520 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\select.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00054920 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\crypto.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00017032 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\rand.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00043656 _____ () C:\Program Files (x86)\Plex\Plex Media Server\Exts\OpenSSL\SSL.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00081544 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\_ctypes.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00111240 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\pyexpat.pyd
2014-12-21 23:31 - 2014-12-21 23:31 - 00689800 _____ () C:\Program Files (x86)\Plex\Plex Media Server\DLLs\unicodedata.pyd
2015-02-12 17:19 - 2009-02-27 17:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2016-08-08 15:10 - 2016-08-08 15:10 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\5d3fdf7962e3a154830b603096be4216\IsdiInterop.ni.dll
2010-09-10 03:49 - 2010-03-03 21:08 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2017-04-03 19:03 - 2017-03-28 22:04 - 02187096 _____ () C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\57.0.2987.133\libglesv2.dll
2017-04-03 19:03 - 2017-03-28 22:04 - 00086360 _____ () C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\57.0.2987.133\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\.DEFAULT\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\.DEFAULT\...\freerealms.com -> freerealms.com
IE trusted site: HKU\.DEFAULT\...\soe.com -> soe.com
IE trusted site: HKU\.DEFAULT\...\sony.com -> sony.com
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com
 
There are 7907 more sites.
 
IE trusted site: HKU\S-1-5-19\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-19\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-19\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-19\...\sony.com -> sony.com
IE trusted site: HKU\S-1-5-20\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-20\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-20\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-20\...\sony.com -> sony.com
IE trusted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\foragentsonly.com -> foragentsonly.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\...\123simsen.com -> www.123simsen.com
 
There are 7907 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2017-02-28 10:08 - 00000855 _____ C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Ryan2011\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{F859B18D-11B4-47A0-98AF-6CBF61886FDB}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [UDP Query User{EB4D2780-8883-4487-A163-5C2131EAA1FD}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [TCP Query User{706C019A-2431-4162-9BE9-3D95F25C8A0B}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{B309CC84-66C2-4C1F-8B0A-E7AB183731EC}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [{78BBEBB9-98AA-4E78-8D46-EC7EAF903828}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3437AB37-5A67-409F-98F0-B61BEF40A4C9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{0C838C23-32AC-4619-86BB-1DB626541975}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Banished\Application-steam-x64.exe
FirewallRules: [{25D253B2-BC06-4D73-A7F3-48712F166FF5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Banished\Application-steam-x64.exe
FirewallRules: [{E8FA111B-E1AF-425A-B972-E46846F3F7E4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{6C7B2DD2-4B1C-4DC4-B3AB-39EAFF52A5A7}C:\program files (x86)\deep silver\carcassonne\carcassonne.exe] => (Allow) C:\program files (x86)\deep silver\carcassonne\carcassonne.exe
FirewallRules: [UDP Query User{07157617-7AA8-4622-B84F-2D8947BACD07}C:\program files (x86)\deep silver\carcassonne\carcassonne.exe] => (Allow) C:\program files (x86)\deep silver\carcassonne\carcassonne.exe
FirewallRules: [{5863A6E2-0C37-4502-BADB-F939EB468D5B}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{ABC21109-BD1E-4626-A1F6-28A4BB8A8777}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{511A2E9D-8654-47EB-8EEF-C36E8B3F935B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ticket to Ride\Ticket to Ride.exe
FirewallRules: [{205DE729-8951-44CA-A00B-1F6F3BF3D44D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ticket to Ride\Ticket to Ride.exe
FirewallRules: [{DE05B080-623A-4848-8845-8660795299CF}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
FirewallRules: [{95EE5139-0793-4277-B0A1-87D7CD0CBDC9}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
FirewallRules: [{A75C42EA-3872-4AE8-AB11-4EBAFC36B12A}] => (Allow) C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
FirewallRules: [TCP Query User{0FB0D458-2F27-4D39-9678-02304DD1733A}C:\users\ryan2011\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\ryan2011\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{8D858DBB-F379-4190-9CC0-09C6F936B260}C:\users\ryan2011\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\ryan2011\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{97DDF85E-6573-4675-AC52-CDCA0A1CD552}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SmallWorld2\SW2Executable.app\Contents\Win32\SW2Executable.exe
FirewallRules: [{E72A7AFA-C105-4A25-BE5E-053EDA3E0A05}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SmallWorld2\SW2Executable.app\Contents\Win32\SW2Executable.exe
FirewallRules: [TCP Query User{3FA02E10-686E-4CFA-8898-496B88373867}C:\users\ryan2011\appdata\local\temp\rar$exa0.606\overland.exe] => (Allow) C:\users\ryan2011\appdata\local\temp\rar$exa0.606\overland.exe
FirewallRules: [UDP Query User{2E96CC84-3BBF-4F2E-AA8A-39871170E0BF}C:\users\ryan2011\appdata\local\temp\rar$exa0.606\overland.exe] => (Allow) C:\users\ryan2011\appdata\local\temp\rar$exa0.606\overland.exe
FirewallRules: [TCP Query User{ED39554A-1E4B-4FCC-AF98-972C6A2A1346}C:\users\ryan2011\overland\overland.exe] => (Allow) C:\users\ryan2011\overland\overland.exe
FirewallRules: [UDP Query User{C12A1365-EF38-446B-8DF1-717F1CAED693}C:\users\ryan2011\overland\overland.exe] => (Allow) C:\users\ryan2011\overland\overland.exe
FirewallRules: [{E6D07D41-F769-4575-ABA6-7AB9A923C059}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mansions of Madness\Mansions of Madness.exe
FirewallRules: [{8682DD35-F884-4BB5-93BC-792A4913AC8F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mansions of Madness\Mansions of Madness.exe
FirewallRules: [{AFA8A48F-97B8-470B-85C7-6F550C2E6437}] => (Allow) C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\chrome.exe
FirewallRules: [{0E435481-A561-45F1-9E94-8C2F200E0C25}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F7015285-3BA2-475B-AFAE-D0DD80877A56}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{5B3357A3-40A8-42AA-B10E-1BFBAB029249}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
FirewallRules: [{AEEFB0D0-53BD-4809-9B89-6A483C488C6A}] => (Allow) C:\Windows\SysWOW64\muzapp.exe
 
==================== Restore Points =========================
 
21-04-2017 16:13:56 Windows Update
01-05-2017 17:26:39 Scheduled Checkpoint
09-05-2017 00:00:06 Scheduled Checkpoint
10-05-2017 10:07:08 Removed Samsung Kies
10-05-2017 10:11:05 Removed Virtual Pool 4 Demo
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/10/2017 10:21:23 AM) (Source: MsiInstaller) (EventID: 10005) (User: Ryan2011-PC)
Description: Product: Palace of Chance -- Error 2203.Database: C:\Windows\Installer\3ab574b.ipi. Cannot open database file. System error -2147287035.
 
Error: (05/10/2017 10:13:17 AM) (Source: MsiInstaller) (EventID: 10005) (User: Ryan2011-PC)
Description: Product: Virtual Pool 4 Demo -- The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is 2203. The arguments are: C:\Windows\Installer\3ab5749.ipi, -2147287035,
 
Error: (05/10/2017 10:09:59 AM) (Source: MsiInstaller) (EventID: 10005) (User: Ryan2011-PC)
Description: Product: Samsung Kies -- Error 2203.Database: C:\Windows\Installer\3ab5747.ipi. Cannot open database file. System error -2147287035.
 
Error: (05/08/2017 08:21:07 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.18639 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 8f0
 
Start Time: 01d2c7f5493bff43
 
Termination Time: 16
 
Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Report Id:
 
Error: (05/02/2017 01:41:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.1.0.415, time stamp: 0x5881b7a1
Faulting module name: MwacControllerImpl.dll, version: 3.0.0.142, time stamp: 0x58a313b4
Exception code: 0xc0000005
Fault offset: 0x00000000000273fe
Faulting process id: 0x9a4
Faulting application start time: 0x01d2c274896d3741
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacControllerImpl.dll
Report Id: 0d1f5db2-2efa-11e7-9208-000acd21436e
 
Error: (04/27/2017 09:19:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.1.0.415, time stamp: 0x5881b7a1
Faulting module name: bcryptprimitives.dll, version: 6.1.7601.23451, time stamp: 0x573365b4
Exception code: 0xc0000005
Fault offset: 0x0000000000007e53
Faulting process id: 0x900
Faulting application start time: 0x01d2bea1c50daf21
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\Windows\system32\bcryptprimitives.dll
Report Id: afc24917-2bb0-11e7-875a-000acd21436e
 
Error: (04/25/2017 03:57:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.1.0.415, time stamp: 0x5881b7a1
Faulting module name: bcryptprimitives.dll, version: 6.1.7601.23451, time stamp: 0x573365b4
Exception code: 0xc0000005
Fault offset: 0x0000000000007e53
Faulting process id: 0x744
Faulting application start time: 0x01d2bcf65ec8a3d4
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\Windows\system32\bcryptprimitives.dll
Report Id: d297bbe7-298c-11e7-875a-000acd21436e
 
Error: (04/23/2017 06:16:33 PM) (Source: Software Protection Platform Service) (EventID: 8208) (User: )
Description: Acquisition of genuine ticket failed (hr=0xC004B100) for template Id 66c92734-d682-4d71-983e-d6ec3f16059f
 
Error: (04/23/2017 06:16:33 PM) (Source: Software Protection Platform Service) (EventID: 8200) (User: )
Description: License acquisition failure details. 
hr=0xC004B100
 
Error: (04/22/2017 05:21:39 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.1.0.415, time stamp: 0x5881b7a1
Faulting module name: arwlib.dll_unloaded, version: 0.0.0.0, time stamp: 0x58af57f8
Exception code: 0xc0000005
Fault offset: 0x000007feeb61f273
Faulting process id: 0xf90
Faulting application start time: 0x01d2bad23e388263
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: arwlib.dll
Report Id: 16d775fb-273d-11e7-8cb1-000acd21436e
 
 
System errors:
=============
Error: (05/10/2017 10:34:31 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:34:29 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:34:29 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:34:29 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:34:29 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:34:29 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:33:02 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:33:02 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:33:02 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
Error: (05/10/2017 10:33:02 AM) (Source: Microsoft-Windows-Bits-Client) (EventID: 16398) (User: NT AUTHORITY)
Description: A new BITS job could not be created. The current job count for the user Ryan2011-PC\Ryan2011 (60) is equal to or greater than the job limit (60) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.
 
 
==================== Memory info =========================== 
 
Processor: Pentium® Dual-Core CPU E5700 @ 3.00GHz
Percentage of memory in use: 94%
Total physical RAM: 4060.98 MB
Available physical RAM: 225.28 MB
Total Virtual: 8120.15 MB
Available Virtual: 2728.75 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:453.69 GB) (Free:298.44 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 86C69001)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=12 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=453.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 

  • 0

Advertisements


#2
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,087 posts
Hi! My name is zep516 and Welcome to Geekstogo!
I'll do the best I can to resolve your computer issue
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, don't continue Stop and ask! Never be afraid to ask questions! :)


First
A few items to fix

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Open notepad (Start =>All Programs => Accessories => Notepad).
Copy/Paste the contents of the code box below into Notepad.
start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-18\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
FF Plugin: @java.com/DTPlugin -> C:\Program Files\Java\jre6\bin\npDeployJava1.dll [No File]
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [No File]
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CMD: bitsadmin /reset /allusers
Emptytemp:
  • Click Format and ensure Wordwrap is unchecked.
  • Save as Fixlist.txt to your Desktop (Must be in this location)
  • Run FRST/FRST64 and press the Fix button just once and wait.
  • If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
  • The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
  • Note: If the tool warns you about the version you're using being an outdated version please download and run the updated version.

    Next

    Download AdwCleaner from here. Save the file to the desktop.
    NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.
    Close all open windows and browsers.
    • XP users: Double click the AdwCleaner icon to start the program.
    • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
      You will see the following console:
    iO5EZayK.png
    • Click the Scan button and wait for the scan to finish.
    • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending. Please uncheck elements you don't want to remove.
    • Click the Clean button.
    • Everything checked will be moved to Quarantine.
    • When the program has finished cleaning a report appears.Once done it will ask to reboot, allow this
    adwcleaner_delete_restart.jpg
    • On reboot a log will be produced please copy / paste that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt

  • 0

#3
Lyanheart

Lyanheart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
Fix result of Farbar Recovery Scan Tool (x64) Version: 14-05-2017
Ran by Ryan2011 (15-05-2017 08:40:04) Run:7
Running from C:\Users\Ryan2011\Desktop\Malware
Loaded Profiles: Ryan2011 (Available Profiles: Ryan2011)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
start
CloseProcesses:
CreateRestorePoint:
HKU\S-1-5-18\...\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
BHO: Java� Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
FF Plugin: @java.com/DTPlugin -> C:\Program Files\Java\jre6\bin\npDeployJava1.dll [No File]
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [No File]
CustomCLSID: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CMD: bitsadmin /reset /allusers
Emptytemp:
*****************
 
Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key removed successfully
HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found. 
HKLM\Software\MozillaPlugins\@java.com/DTPlugin => key removed successfully
HKLM\Software\MozillaPlugins\@java.com/JavaPlugin => key removed successfully
HKU\S-1-5-21-1237553287-1429794397-2156527687-1000_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04} => key removed successfully
 
========= bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
{CDDDBCC3-21B6-414D-AFB5-DC293D8A67AA} canceled.
{F2837332-BA41-4FBD-A988-72AB9AE1B63E} canceled.
{D5B917CD-B236-417A-9641-9601CE3DF158} canceled.
{5CC32EEF-683F-49AC-9ECE-9774D6F59903} canceled.
{94B15CBD-FF50-4468-8248-3318CAF6997E} canceled.
{8286EA36-DCEA-4B35-B95B-D7AEA7A4B97B} canceled.
{E1417DB0-1A02-4EBD-8A4F-CB4FE70A67AD} canceled.
{B4E8C3D7-E2B7-4972-B82D-6962404EB11A} canceled.
{C134D544-6AFA-4A30-B8D5-6D1F9ACEE09D} canceled.
{36764180-8577-48A4-8B53-A1D3807E3021} canceled.
{04746BD5-D8DA-4B9B-880F-D3EC6ADD1604} canceled.
{9CF11AF0-CD17-4919-A0D6-09327750433A} canceled.
{C95620C5-FBFD-4975-A8EB-9DC91A69503C} canceled.
{DCA34D41-6D01-4D8B-8CC6-5141FFE1AB49} canceled.
{78E2ED3F-8F8E-4EDE-8797-0D7DFBB51112} canceled.
{BC8B8258-E912-4D14-8B70-ADECE7D7B88D} canceled.
{5D6B9A0D-F96E-4F8F-A8CF-77B8C1BCCA2E} canceled.
{6957B754-A3CA-4D97-823E-7F69A6A0AB0F} canceled.
{C1F8C277-3CAD-4AC9-9BC4-C8D4F54DB5EC} canceled.
{91EDF94C-4E1D-4E78-8964-4328E0C00055} canceled.
{EA881E2A-75E0-4F2C-B689-BABCA6C23E9A} canceled.
{FA376B3E-114E-40D1-997B-F1FF3250425C} canceled.
{711FA526-50ED-44C1-8DCA-0248CCAFE1F5} canceled.
{3FBF0962-0097-4B1B-8C23-D0683764EFEC} canceled.
{79E893AE-8F01-4CF6-B0E2-0433C6028AE3} canceled.
{9E7AF1C1-542E-4A08-B418-2DC645C73986} canceled.
{FACFE341-13D5-4A44-B256-F166C7869AA4} canceled.
{7046A126-8FC5-4A68-BBFC-2E1F020A5880} canceled.
{86B3B317-1088-4464-A8A1-74FCB301ED9D} canceled.
{F333E703-657F-46EB-82D3-4065CCD3847F} canceled.
{58B31834-C804-46E0-A634-1B956C4D929E} canceled.
{69038D40-5A0A-4BA5-BE60-EF5A799C0A3E} canceled.
{E5A7C7E6-0FB4-484B-9184-49769FBB6C0A} canceled.
{4D37147A-0901-4371-84B4-F49E4032B5ED} canceled.
{86D15BBB-30D6-4228-BAB3-956F1C538514} canceled.
{C1402A91-1B77-4094-8C00-750430B34C3E} canceled.
{1FE5D814-6D3D-4CBF-B230-B2083ADA5E0B} canceled.
{CB698F51-7440-48B3-A75E-44E9C4ECA527} canceled.
{BF8A1125-E527-489C-A831-422AD58B0B04} canceled.
{3168B6EE-2A2E-409E-AF84-CF0FD75F1038} canceled.
{E6A0447B-97CD-4D73-86F0-716A0B8E3FEE} canceled.
{B9C8A9CB-790F-4142-B781-76A08A54F037} canceled.
{A30AFB40-BA3A-409E-8750-D55035C1FF18} canceled.
{EA1AD021-1B71-4761-81F7-F467DDDA012F} canceled.
{BEFD8C18-77EF-490B-B9C1-C64D3765FAF1} canceled.
{E6532159-B30C-4ACD-A62A-78DFA80E7EE7} canceled.
{DE75A2D5-DBB9-48E5-92E4-C1A7FD76F415} canceled.
{7E8C911F-D859-4BE8-B5CB-51A7DA2FCFB7} canceled.
{C0238ABD-46C8-4EA5-A38E-7A7761DEB9B4} canceled.
{F9E2072D-8649-462E-9F64-A872F0849069} canceled.
{ADC39740-0E74-4741-87AD-E5614187FF1D} canceled.
{9DE330B1-1362-4BE2-AD3B-8969A143A56E} canceled.
{CB08820B-1F8F-4E33-AFB6-2A5D771FF068} canceled.
{ED0F7801-5A96-43C5-BBFD-A7103AE611A7} canceled.
{D15E9B19-E298-4B6C-849D-32E1D583250F} canceled.
{9F389A5A-9B1C-43C9-A1E0-1B95255814D2} canceled.
{CFE30160-8667-446B-9450-83500EFF9F46} canceled.
{1548D992-DE77-4C07-B9F7-5B6AFF97D507} canceled.
{53BF02CF-9E47-40B2-BC2E-2058A1906386} canceled.
{93F2CF0F-8EB1-4703-A672-AC714EBCB134} canceled.
60 out of 60 jobs canceled.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 21907163 B
Java, Flash, Steam htmlcache => 21357197 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 763601255 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 0 B
NetworkService => 0 B
Ryan2011 => 7776968330 B
 
RecycleBin => 544 B
EmptyTemp: => 8 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 08:43:47 ====

  • 0

#4
Lyanheart

Lyanheart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
# AdwCleaner v6.046 - Logfile created 15/05/2017 at 08:58:01
# Updated on 24/04/2017 by Malwarebytes
# Database : 2017-05-14.2 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Ryan2011 - RYAN2011-PC
# Running from : C:\Users\Ryan2011\Desktop\Malware\adwcleaner_6.046.exe
# Mode: Clean
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
[-] Folder deleted: C:\Users\Ryan2011\AppData\Roaming\Yahoo!\Companion
[-] Folder deleted: C:\Windows\SysWOW64\C2MP
[-] Folder deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Toolbar4
 
 
***** [ Files ] *****
 
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key deleted: HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{7D831388-D405-4272-9511-A07440AD2927}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{8233093C-178B-484B-979E-3C6B5B147DBC}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}
[-] Key deleted: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\Software\Yahoo\Companion
[-] Key deleted: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\Software\Yahoo\YFriendsBar
[-] Key deleted: HKU\S-1-5-21-1237553287-1429794397-2156527687-1000\Software\AppDataLow\Software\Yahoo\Companion
[#] Key deleted on reboot: HKCU\Software\Yahoo\Companion
[#] Key deleted on reboot: HKCU\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key deleted: HKLM\SOFTWARE\Yahoo\Companion
[#] Key deleted on reboot: [x64] HKCU\Software\Yahoo\Companion
[#] Key deleted on reboot: [x64] HKCU\Software\Yahoo\YFriendsBar
[#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3038A20B9089EC34D8F74220191FAB30
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL
[-] Key deleted: HKCU\SOFTWARE\Classes\ChromeHTML
 
 
***** [ Web browsers ] *****
 
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [4067 Bytes] - [15/05/2017 08:58:01]
C:\AdwCleaner\AdwCleaner[R0].txt - [11219 Bytes] - [12/01/2015 09:14:21]
C:\AdwCleaner\AdwCleaner[R1].txt - [1408 Bytes] - [06/02/2015 15:45:57]
C:\AdwCleaner\AdwCleaner[R2].txt - [1537 Bytes] - [08/04/2015 10:40:56]
C:\AdwCleaner\AdwCleaner[S0].txt - [11431 Bytes] - [12/01/2015 09:41:54]
C:\AdwCleaner\AdwCleaner[S1].txt - [1482 Bytes] - [06/02/2015 15:48:27]
C:\AdwCleaner\AdwCleaner[S2].txt - [1609 Bytes] - [08/04/2015 10:42:59]
C:\AdwCleaner\AdwCleaner[S3].txt - [4621 Bytes] - [15/05/2017 08:54:59]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [4653 Bytes] ##########

  • 0

#5
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,087 posts
Next
  • Please download Junkware Removal Tool to your Desktop.
  • Please close your security software to avoid potential conflicts. See Here how to disable you security protection (Anti Virus)
  • Run the tool by double-clicking it. If you are using Windows Vista or 7, right-mouse click it and select Run as administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete, depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open.
  • Please post the contents of JRT.txt into your reply.

    Next
    Please run a Malwarebytes scan also and post the log report.

  • 0

#6
Lyanheart

Lyanheart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Ryan2011 on Mon 05/15/2017 at 14:51:14.12
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{003D8DD3-410B-4D5F-9B70-FE4AF4FE4231}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0253FFCC-C91A-4D2E-8A6A-9762C45E5B9E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{027B33B9-D0DF-447A-A09A-B3BB237A9248}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{02C05C4E-8EF4-4E51-A9B0-DBE1142E350B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{03A5C846-C48E-42FB-B75F-C4A326A4A936}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{03D215FD-3211-4381-9429-2F76210D97EF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{049BCFE5-E235-459E-A160-6008BBA0CC6B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{05BC620E-C370-4322-9AE3-6970723D3822}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{05DF43A7-809B-4A1A-88D7-17D550E8B50B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0610C5D5-43A6-4A1B-BC1C-F21CC36F872F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{06133E1D-EBAF-4560-9200-F1222FC75749}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{064CF1C7-A0CF-483E-9494-975583D08719}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0692DBCA-C0DF-44BA-9C6B-0899963A47E2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{07840B8C-299A-445E-9BA3-A82145B31B17}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{07C6DAB6-AD3F-4979-9406-693C71CABB49}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{07E30379-32FF-4DCD-B24D-36299FE50D58}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{08C7F392-7C2B-4E13-BAE6-107FC0FDE761}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{094EC458-C731-4A42-951C-626C4F34B359}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{09878591-9889-48B5-9BBC-5EED88599760}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{09A9878A-6080-4F5E-8305-88A177CBC5C1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{09C804DC-CE85-42A6-B8AD-71B535CDA2E3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0A2A6FED-C6BE-47DA-A6B9-A399D3D0D227}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0B1FE0AB-9681-4CDC-8704-0E4CDF790B1C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0B4AAEAE-BCB1-49A8-94E5-C4DD70EF7A97}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0B777F6C-FE1A-4412-A64A-DF86EF387AFF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0B889842-372D-4C6F-8034-DB14383728A8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0BD22029-B0E3-4C6F-A9FA-5F174721F0A7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0C04784E-7984-4642-A9B6-608704C62A4E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0C5E97BC-8C74-4584-8AC0-8BFCBDAF9BA2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0CD252B4-5261-4250-9669-ED09EDD50CCF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0E6FA19B-1FF2-4553-8777-FC97D516615D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0EEF035D-1D24-40E7-B90B-0ACC664CE41D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0F2BBB0E-3D4B-4A6C-9D7B-C30726B18A60}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{0F583F58-6E88-4678-9A5D-25F950C14595}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{10638205-004E-4F1F-8FA3-B547417351E9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{107659BA-4DF3-41E9-93C5-CA9F6AC79B17}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{11263B33-A360-47CB-BC2D-66779D71C3B3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1135A298-3154-4512-9F4B-925CE3B55877}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{11FF05B5-0800-400F-88D1-F70E5BE2364A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{12D756E6-6534-48B1-AEE0-A3D23743E327}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{13EB0C4B-FCFC-4B0E-AA4E-F25FF1135E84}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{14506592-790B-49B5-AA94-6F61BF2A836E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{14CA19ED-6882-4195-A201-D20DFA7E3947}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{150DD8BA-5DA4-47AA-99FA-6DE6B5A09BD6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{15145D28-599F-4A54-AA33-43DA147F3B86}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{16429E12-EB66-4C3B-8F4A-1E4E62910E5D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{16ABACEA-8B83-44AE-9A2E-6F30A9F436AE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{175ADA9C-E541-4268-BFB4-461B1C60476B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{178061BD-2192-4B35-AED9-A1D6EF44AB6F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{178551FA-C17A-47B0-A4A2-15FD21BA8208}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{17CFE4F8-52B5-4B05-AEA1-7BF556100641}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{17EE57C9-92D5-4A37-9E39-7B0BE35DA023}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{18C1634E-20F0-4897-A9E5-FCC724C56CAE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{19D3AA10-B423-4C63-8C39-C39CF72DC33B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{19F0D5B2-D72D-4347-9650-4EDB0C72FAA4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1A14D402-EC8E-4848-B0DC-1EC86EE95654}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1AEC60C1-997D-4DD9-84A5-6F627AE6D73F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1AF0C544-9432-4B48-8562-952588B40A23}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1B1D081C-C864-47BB-969C-CAA5FB409757}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1B328615-BBE9-478F-AE2C-80EDC13C9341}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1B65113B-AB9D-4A16-970D-BD5FA021C01D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1B941DF5-757E-4FB1-A2D3-EEFE07003D04}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1C6963BF-134F-4644-8415-84EC5823CF12}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1D3038EF-AD75-47A0-AAC4-CA5EA52C3102}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1E328CE3-7537-4363-B48D-E67DA4F163FB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1E5BA22D-5B8A-461D-8DB1-FD28865B96E3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{1F6ABACD-763F-4949-BFD4-CDD794F99DFA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{20BF86AB-B9BD-485C-B7F5-4B71C512F4BD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{20D03ABA-B8B0-45AB-A8A9-7EA1F418DB8A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{215107F4-21F8-4A1B-8938-F2D637865F7A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{221F5D2C-36BD-4AE9-8EC3-ADEDAA4BCFA3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{22D482B2-3B0B-474E-AF36-B9312C498C03}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{23B30AC5-18E2-4197-876A-04D59E5BCE2B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{24399964-FD16-4056-BF8D-15FB47B64FB7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{24BFDA4F-F51B-48B9-976D-06A970989680}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{24D781BD-A3F5-408F-AF1E-C826C591442E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{259F7CFC-4A6F-4361-83B7-6631B6D528B1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{26338839-AEB3-4528-9549-BBBFCE4B0F0A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{268CCDFB-70E5-4CA5-8F97-ED430A8FE22F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{26B5434F-F8CF-43E4-84DE-9BE7EB8727C1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{26D5AB9D-7E92-452C-971A-99F3EEFB0F61}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2797A039-B3B8-4150-8268-2715C30E3E9D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{27BCD41B-47E0-4C44-AF4E-EE8CD2E09EE6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{27D27448-806D-4937-95A3-0C9502D9FB42}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{282813B2-E4A5-44EA-9A54-B74D0E3F031E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2832ADD3-45B7-48EE-B5D3-6A5EE7D3F0BC}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{28408E5C-9E9D-45D7-9E7D-6226E00BE32C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{29231387-C66E-4595-842C-B1A042292B9A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{295AC9FE-6DBB-4AF3-BDCF-23F050898D63}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{296764F4-3210-412D-822B-734DF0761E7A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{299D5961-5061-4077-826C-8FA0DFEB8087}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{29CEB29A-34E9-45C7-9718-2C1C38C3AF65}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2A064B60-6BC9-419E-8A06-7DC674DA8E16}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2A4F9D49-EDEF-4FBA-9493-C753A958A523}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2A9D3F21-47E6-47F8-98F7-6A9ED8CCCF41}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2ABD1C66-472F-4F69-9522-61791E72754F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2AC3B657-CAB2-45B6-B4CF-04152B3289FB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2AF4D731-4B24-4F4F-9CAE-CC79BAC5F048}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2B45B18B-4EBE-48C9-92F7-08A6C304FEAB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2BD36D06-8D02-4436-87FE-7E1837082BC2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2C139BDB-AD3D-47FE-9314-57FF2EE130A8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2C6641EF-ED5C-4322-B548-1B30C2CE3D56}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2CCBDF1D-1509-4B8F-BB83-D96B91252B35}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2D75E713-9405-4A22-B439-70C7F9B60B75}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2DA14968-0A71-4BA3-A13A-F28953BD9585}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2DE99A08-4BEE-4455-B379-12F435881447}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2E107190-672A-4E0C-992C-992F9EB8F8E6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2E1A7D18-90FF-4998-8AE3-61A19210E947}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2E47EA39-37EA-4583-84A1-D676F1F2B032}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2E69996E-C035-4CBA-A926-8A6F84676E10}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2E8DD783-0047-49A7-AD90-F8446635A6A6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2EBFD363-8D36-4887-827A-42046496A7E2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2EC1C7F9-9745-4DDF-9443-9F1BAC59A953}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2ED3C739-C545-441F-9CEC-035274DC4852}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2F3D584C-CF0C-4D93-9E3A-3121A67667F0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{2F7C4013-AE58-44C3-A3DD-D44378F53605}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{305811D2-5A51-4310-93D1-FD09B23BA4AA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{30B0913B-D844-47E5-BE50-260074E48AE6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{30F4948C-2D6F-416D-8796-D14CFA57DFF9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3110D190-90D0-4160-9AC1-E2F37DA7E789}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{311E9B53-4B5E-4F17-8DFC-6AEE8DD81160}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3177E015-7966-4AA9-8317-1630D888727F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{32AAD89E-2332-4B6C-BCF3-04052551B868}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{32E42171-0814-4A8F-A423-F4D1BBEBC9D2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{330CF7D3-B86E-453A-B574-82801D5ED5E7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{33C3C08F-C0E5-4057-868D-C867DBA82EF5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{33D7E3FB-6B49-4E01-9FC4-3E09B08428CA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{345729FD-8902-41F2-8CCD-0268C1C1B821}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{34EF7FCB-CB47-45D1-AA01-AA877861A5E6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{354D8D9E-D8F0-4DA3-A000-7941F058EB19}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{359A1661-F1C0-48BD-A158-877C358AFBE5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{35ABBE4D-8609-4122-9B7D-83A655833237}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{35CE7DFE-49BB-4FAE-B4E0-1BD9DD15B64C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{35DFBB9C-FB39-42AA-BF78-C77D41366F7D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3692F5B7-84AC-48DE-B3FD-2F3727622089}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{36F35BE8-1242-4852-B7AB-194D51A75196}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{36FCC92E-49D4-45BA-893B-6408B0BF2E2E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{37A9A1A1-217C-406E-A72B-699D636AA322}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{37FF8EF3-9C6A-4A6B-BCA5-ED557AE742AE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{38020161-1E1C-426D-AAE0-F6FB39111727}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{38116968-C93A-4749-BCB2-1D574F03DF37}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3826B251-8D16-4849-9477-F6378DF51F52}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{38728F76-16C9-4327-B187-0AA8E2F00AC3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{387A589D-5F38-4EE9-B9CE-449DF0BC61A3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{391FEEEA-AA8A-4792-B7A0-89D96DE66927}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{392ED078-0795-4F25-8721-E8F7A1C28964}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3AE4BE39-0588-4F5E-916A-2BC205A06D92}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3B359465-2C03-484A-AC31-CE75B4CB78AA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3B38091A-C97F-4101-8DED-F9F4608020DB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3BB019AA-C611-446F-9690-B7A2E5715E2F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3BF419AB-798D-43BA-A6ED-489EE75D4427}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3D0E06C2-F666-4DE3-B0ED-19257044F1BD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3DD46C44-13EA-4F92-855E-8EC7F745131F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3E44E6AB-A416-4077-920C-7713FE92AA2B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3EBEAE4E-1519-45D1-9501-8DFD1778902B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3F42AA14-8F98-4FA6-8D05-669BF254551D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3F4C643E-C570-4785-B7AD-C4D79F4ED81B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3F6C5470-600A-46A0-A4A0-B08CC6B2CE22}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3FB1BD94-7F95-4E84-839D-7D9DE26FEB1C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{3FE4D635-24F6-4E9D-840C-9480DEBAFEC4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{40258797-A3AF-4572-AC8E-50418DCDE1C7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4055891F-4CC6-4A4B-91A0-7E0B87247D94}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{40DC6A86-9537-4C60-AA13-83A1C510F0BE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{41350667-3D43-4C4B-A753-067A5D0F0EA1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4192ABF7-3CF0-4F22-AB4E-AE81EADCF3A9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4301AD20-693C-4467-BEA0-39F4CD50D596}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{43E6B25D-0606-4456-B4D3-2B84DE4A216A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4414BF03-A835-44DC-8942-B47D49A796A3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4476C012-6EC4-4296-A5FD-8B8CAACE7AA3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{45899AD4-E369-48C9-9B6F-2F56B27A5369}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{464C198B-94C3-472E-BB62-835D5780D6B2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{46F2672C-11D7-4649-9696-144163874269}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{47007508-8995-4C55-9624-9D328A52BEE5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{47224DDB-ACA9-4FBB-A109-2CE7A98C8BEB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{47D3BEC6-C714-4037-8C02-C6D18EE2FD81}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{47E3ECEF-6EEB-432B-97E9-F9C366ADC48B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{480AD2A4-4872-4D8D-8EF4-971560AAECC0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{48755364-AE4A-4CFF-B9B6-A14A36C0BC12}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{488EE70C-D8CE-4A92-ACE5-F50540C0D809}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{48F9B72B-B5FC-4F28-83D9-702158CDF769}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{49475E60-A4B9-49C9-9B69-6413591A7420}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{49586467-FB1B-4F2A-A31D-7E35B4896740}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4A0416D6-3AE8-45FF-93CF-0CAE341666F7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4A97DD1C-D633-42A5-BA88-75B69BD24787}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4BF1C81C-BD35-4CB2-899D-3F4103BC4C9E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4D223147-AFE2-4BD7-88F1-3A1B059C9F39}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4D33F489-1E9E-4DD9-9CE6-CADC63FE45E2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4D35B0F9-6E0A-444D-B9A1-634EFEA8C282}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4D9E1DD4-9E55-4B84-B13A-3657168583A6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4E133436-7588-4CF7-BB5B-2AC34703C188}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4E6C7930-7C5A-468B-80BA-04EFAB4728E6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4E724199-9FA1-43F3-8C6D-63BBD3033FA8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4EB2DD59-30C2-484D-A37D-FDAEA5609998}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4EF7FA5C-3A09-44E3-9630-4170703236F9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{4F84B4BD-0717-46F3-B4E1-2B5FE92577B1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{509017A8-2E6D-4B62-9F3A-2D2142203DC1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{51B5C449-B9F8-48BA-9C8A-A50C627BF95B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5219B9E2-C7F7-4A4B-B0B5-EFB4984D7092}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{527C912B-E28D-4055-901D-347601D29FEA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{53643F00-6C8E-4F44-BA3F-912870471FB5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{53AF8641-6332-466B-8EEB-77DC6AEA9D49}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{545009C2-143E-49E2-900C-2B7C5D7FCFB1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{545E57FB-845A-4ED4-876B-96A554ED9515}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{54A274CB-EDB7-4D42-8548-662955156BD5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{54B33C8C-2D98-4392-82C1-23F516970FE9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{54B3FA86-4B89-4ECF-8E4F-0A28F8C2474F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{54FE4BFC-C8E9-4486-A66A-F77224EDAD74}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{553A8746-3214-48EF-B358-5DD247B1FBCB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{55444E80-C5D3-4775-B265-D86368957EA8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{55FE97F4-0FCC-48B9-BF20-94408196B41C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{579A69AF-DB72-4F1A-B274-AE8FABD9D3B5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5867C5B3-5E9C-42DC-AF8C-46D80DFD2E7D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{58702177-305C-4CA0-9A67-52910F6968AD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{593C1C7C-562E-411A-812B-4B5FECAEE90B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{59693E62-F61E-474D-81F4-9C1DF1090F69}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{596F59E8-5EB5-42F2-988A-46C6A2E9DA4A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5A1A2058-BAD1-4A79-BF06-B0BE6E69F09D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5B1CC030-5292-4169-9A0C-0162AA0B1063}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5B3B051C-15B3-4DC7-97F1-39F87A00FF7C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5B90D527-C508-4651-AB3B-BDF34CFF28B1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5BF1A27C-9225-40D0-87AA-E027ADAAFE7D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5CAD7216-F442-4221-8F1C-7B517D04BA03}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5CCFC338-136C-4F84-ADED-D5986B589F39}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5DC45DF0-7D90-4D2C-ACBD-0DFE1A644CF5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5DC7FAC8-CC18-4BF7-824C-DDC7C5CEF78B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5DEC4DAD-FAFE-42E9-8CFB-2D8DAD529DD2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5E412142-62D6-4C61-A39B-0F0F8BA5AD56}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5ECAFB2B-D31C-4138-923D-1872E608B738}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5FB7662F-B6C3-419E-A049-627FFD30FF27}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{5FCF94AD-3FF3-47BC-8F71-7AA5AFF3E8C9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6001999A-F5C2-4B6F-B8D6-070008892071}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{603EC920-8591-4B84-A8CE-2871A80E8B4C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{60CB4B11-DFF6-465E-8F95-57030E5EF3F5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6211625D-F6A0-4FDF-A5E3-3D414B49D2FD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{62CFBD63-CC6D-4465-AD98-0696C04F2ED2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{62D882F4-1E0D-409F-ADEB-0E2F65FCD741}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{63145F78-2FFF-4FE5-AF14-AB4C26CD65EF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6324943C-62C7-458E-8ECC-0D10ADD16E91}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{63DD2843-8CA7-44B4-84D6-14404C8DB434}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6463653E-6F10-4839-AFBB-823F1838E3FF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6486FA1A-98A7-4549-8E54-27BA2ECFDF5D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{64D211DB-ABD3-46BF-BD71-EED4751F0665}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{64D43159-44CC-45BE-8376-FA9AF7AD0C84}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{64D4C9C9-E5E1-4B93-A379-A238D7778FA3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{65156907-99B6-4023-A183-FB11A731F208}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6520D94D-3B9C-49FB-85AF-266F7A252CD4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{657B4E73-81AF-4F0C-B230-C8030F1D320A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{65B5219C-65F5-4D61-83FA-754922313B8E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{65F850E2-9780-49AD-A541-7E36593A3651}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{666EA6A9-8996-4F06-AC12-AA745A247270}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{66758F5C-BEB3-455E-A0EB-1BC1E3046A4F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6684DF2B-F857-4055-93C5-6AC4D4A4620F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{67AA2CA3-EC07-4CA4-AFB9-E59DFEE373D7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{67FA142F-8885-4D43-8C55-F23436B77D25}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{68435632-107B-42A0-A823-AD2519F147F4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{687EDABF-6152-4750-A07C-F94A767AD90C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{68A76980-547A-4D43-BF30-0886866BE031}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{68B7364B-AA12-4126-81A0-64796E1284A4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6948FC8D-B8EF-4E1E-81F6-7D89907DD040}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{69942D86-B4B3-41CD-933C-C6DE14C5F6E8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6A00E796-DD14-4C8B-B0CB-22D274839481}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6A666850-B5D3-49C8-9C9F-A4AEE173662D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6A98B9F2-8A6C-49D0-9A8A-AD4A71B03CF5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6AB3807F-4130-4BEB-9922-419050203461}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6B939AED-B134-4E79-A60E-F4D8BE4D48B4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6C05B8EF-8689-42F6-BA47-C2543B02D031}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6D328018-8439-4FF1-9C91-494AB2E549AD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6D54EB3D-AA11-49DF-97A7-DE101A883EE8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6DFA4565-8805-4788-8AC1-6F0B7F74472E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6E2A8F7F-549C-465D-9EF7-259B79F937DD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{6E6EBAB8-4432-4074-B7E8-534D6F7EFACA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7032A3EE-544C-4FBA-BE22-15DE1961A93D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{713DB25E-C041-48B0-8E5B-BC9065BF5B6E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{71AE9A6F-630D-4FA6-AC2F-F204AAEBCFF1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{721FCABE-F34A-4060-B9B3-DC57B8FD03F4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{72741B0E-6EBA-410E-8E72-7A92C206820A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7340A850-29E3-4163-9B4F-3FB8EDCEF243}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{73BF7B51-7D3D-47EA-A0F9-BAE1942E50AE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{73FBFB7A-EF23-4D28-8650-C765DAEC8452}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{74571FD0-5581-46EA-B049-5A221074A7DB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{74894273-3340-43A0-957C-2C96DFCCA3CE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{74BD50E1-065A-4357-BA2F-DFE327FE68CA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{769AB4A6-0F14-4BDB-A96B-2C9814A6C4E5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{784CD009-2C20-4575-A7AD-50C2E6A3765E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{785A6E4F-EE2B-41D9-AF82-E5E2E2FA1EB8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{79E24931-A5DE-47A9-BCDB-5B2351AD1B50}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7A0237DD-59EB-4C59-BB3B-FF6A0CE47DE1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7B3AC8CE-EC80-4B40-8524-C6453519C480}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7B7BC2A7-5271-4DF2-9FB7-F5506DEFB3CA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7B97078A-CB4D-49D9-8663-D07407868B56}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7BEDF894-FE4F-4ACC-9654-980C9FE8A0EA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7BF92EC6-AD81-4757-B3BA-50386C835881}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7C670A6D-3EE2-4DAE-B626-FADCE1CC5C01}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7C9143CD-3F9F-43B7-ABFC-458E9DBFC5CD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7D0933CE-EA97-4E56-94E8-26A2C9230B17}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7D21E78B-B642-4160-A008-5CF2E049226F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7D2946D1-1A6C-48DE-88F5-79ECF5F45784}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7DBBC78D-2891-4CB3-B88C-D4E8E38060BA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7E1958F5-7E90-489C-9D1E-39200A613E9B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7E836F98-AB1F-46D8-8D3B-75EFD963235E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7F36D547-987D-4561-890C-1E93537FC4DD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7F506675-710D-4F10-A006-C2C07ACAB4BD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7FA3ECB2-854B-448A-A0D8-B76B0A448F46}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7FA8985C-26EB-4F68-8EEE-0E533AE093A6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{7FF7391C-0231-47FC-8ADD-88CC30008B79}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8002BD61-E3A2-4900-BED0-6EC98BAE91D6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8022534C-F44B-4404-A95F-42F5A67F33F9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{805617DC-50B0-4FAB-ADD8-F8EEE036A175}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8059B459-6E67-4C5D-9F37-A17168B82C91}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{80CCF0A6-6C88-4A5E-ABDD-60F7A0203CF3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{810A0C3E-8E43-428A-8F94-588DA177AE19}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{818F308B-793E-4B74-9ED1-515612AA4501}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{81B0A074-0AE6-48C3-8700-0AFB15735637}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{81EA28E9-868A-4F5A-A48C-794663E200B4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{82C0DC82-C649-4496-82D1-734143BD37AF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{833FACD9-67EC-48F9-A8A7-61B265CBF1F0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{837B2B20-0710-45CA-BCC6-CC2D1BB74AD0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{83934FF3-63CA-44E4-8032-55F221FF483B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{83AA441B-1496-4B52-BDE2-9375F74D6797}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{841403B5-B95C-472C-9A1E-34F07F18FF67}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{849709D8-0C41-41A3-80D5-5BB1445012EA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{84A969E5-A16F-4E51-A347-C1FB460E28B7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{851F4B93-1DA3-4842-8DF5-AF1D7D3BA9D4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{85A82C1E-B6A2-414B-A361-70CCAFE8AA23}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{86108C3F-1138-48FD-B87C-B0673407632A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{86203DC6-6757-4066-9722-6F38729A6914}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{866D773B-5754-4872-AE5B-346AF418676B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{87024944-80E7-4592-AE30-EC697486C175}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{88965A44-55E9-4559-9339-62D232A666EE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8A90F674-AB66-495A-8AE6-1F4646BC2316}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8B1DD283-AD58-4944-A73B-8C406D8BD47F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8BA8908D-4129-4740-9F72-59A8626503D1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8BD5C549-3234-4DEB-B389-CAFF7A359BDF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8BDBE57C-9BE2-4CFF-A07B-025EDDE14774}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8BE322A1-D29D-4AEC-9EB7-F4D46DEA24D0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8BFED769-6048-445A-9DED-618F9E012B41}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8D7719F6-5806-4300-80A0-F6793BF538E1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8DEF7470-D0DE-4EB2-BEBF-11BA8B33C4F6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8DF26464-A2ED-463B-B9D4-1CE6A7D84CDB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{8FC583FC-434A-495F-B506-91BC6C88EF8A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{90771DF1-25BF-4AD6-B6DB-85B14ABAF87D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9088C7C6-AFF2-4A05-B835-20647D89DA15}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{90A7E133-5806-4438-BD73-47BE2F6B5F46}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{91455453-234F-4B2F-B401-A0827E648F0E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{91890CBA-4382-4698-BE6F-8BF1B9DDD03F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{919FCFBE-0273-4DA5-82DF-C48A1BADE94C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9211F48A-088B-469E-9A00-A639530B8C34}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9236068C-70E2-4691-85AD-3802178AF59D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{92AC3C7E-0EDD-4B14-BC79-2847C243223C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{92D13B2B-A2A6-4F39-A5EE-C65F793980B8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{92EE76BA-72E7-4D40-9BFD-620ED9BEC352}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{93D3FEA7-E83E-4043-A1C7-5C26B9822C2B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9446E474-1E4B-4C3E-B7B6-884739A49636}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{94646BB8-1B2A-4A40-8CA5-AACF627F6A72}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9467483D-8757-413B-AAE4-61CCCB0BBDCE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{949955DC-D506-469F-B61B-7105A25AC4DA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{94A64DB6-9C2B-4F2C-8DD2-E00709B25426}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{94B19722-50C9-413E-AD22-04C9BFB6FF2E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{950F53A1-0F47-40F3-BDD6-481D03113979}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{95184A2F-4E16-4B14-A4A4-3D148B305C9F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9522377A-0C93-442C-827C-AE76A268C955}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9591091F-0F53-4275-97CA-207A2A27E8EE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{95A579E3-6D3A-40DF-8FE5-636E3413BD9B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{95D87223-AD0D-4ABC-8E20-5DAE49CEEF27}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{95F1A6D8-2742-4337-83A2-27E73242E5B0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{967E77EF-C221-4CE1-9CB3-80685DE7B605}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{97ADA2C7-2320-4A1C-AE38-506966DCF731}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{97D28246-5191-46D3-B8A3-F1060286A84A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9836245B-8900-4C27-AEF6-D7D366D109D5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{98643078-945D-49DE-A295-73B56973CE7E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{98A43D75-86D5-431F-8763-BEA68C7EB42B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9931CD44-842B-4DF6-81C1-CC81587330E8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9983D8DA-11EC-4E2B-8B63-0A534B75F20B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9A8CA43F-F60E-4F32-B85F-5636A6458699}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9A9096C4-66F3-45F7-99DA-AEC14BA43E04}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9AA0A22A-3F45-4EA9-8A9B-395412EC485A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9AFF0B81-C430-416A-96AF-FE599CC53777}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9B6981D9-0BC1-449B-BCD0-9A699E73CBBC}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9C13B986-8CC4-4329-BE8E-14311FF91380}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9C42BC5C-8A96-4579-9914-27DAC168DB30}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9D07FB32-AF34-4F93-9BB9-A5C1FE1C0A8F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9D343187-CE96-45B6-B432-9031A367907D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9D3D41C6-D960-4FA8-BA43-C1D5392D115C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9DAE8030-E4C1-4F16-9891-9E0E0236533B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9DE22421-245E-4045-94F2-686F74D3D558}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9E1D4590-DA38-43E0-8441-695635DA5D4D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9EEEE133-B5BC-4D73-947B-A19E17B54497}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9F3C6F68-DAF2-4C35-9161-3CDDEDC0748C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9F802805-F55A-475D-884B-A7DE960EC351}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9F83981E-CA4C-4F8F-984C-92EB780A380E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9FAAC371-347D-4F52-B446-5439AEFB06C8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{9FBDE7BD-CC86-434E-964C-B9611DF23F0A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A23A58E3-F18A-49E9-B7A8-287AF3C2D481}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A26A3DC9-BE08-42C3-8E00-82AAB9A5F958}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A272F5A0-47F8-4C51-8A8A-14E19335FB13}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A290FC84-9769-4D4D-967C-501081E5671A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A2AFDF3A-FABA-4451-AF85-1CAB738E781C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A3CCC380-DC74-47FA-8CCF-B338078DF30F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A3E8B2B0-471F-4D95-A906-470657DDD122}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A51D1155-272E-46C0-84CB-5C3A879EF11F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A5254D92-F9CA-4CC8-B788-2E9ACD6F6FFE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A62AB0C3-46AC-432D-9453-4A2E9B622476}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A63A0C74-C476-4A6B-BE13-177FB4E6087E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A647A990-723F-40D2-995F-3F59EAC21803}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A71A95F8-8546-413A-B690-92C09B1BFACE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A757D45E-07E3-4F62-B096-498D577E6B10}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A7C46F7E-CDDE-42C5-B70B-9FAAE18A6C97}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A7D5F45B-0850-4064-ACF9-3E0E9FC84E23}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A918DD34-3CB2-482F-92D4-3675A67563FD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A943BAF5-4BE7-48B0-84C0-C29F740D680F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A9536B23-AB51-4504-8EE4-BF99D3CB8E25}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A96CAA7E-521D-43A2-9614-787CC59923F8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A97EF8B8-82D2-4F89-8443-5F2D46BB2E09}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{A9997DAA-87EA-4562-88F0-C3653F571494}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AA734D3F-1B68-4E44-A21D-8453F5BEC264}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AA76BE7D-BD68-4FCA-A4DA-DE340CAADBC4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AB2B906F-67F8-42BF-A471-8DFBD3342416}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AB4B1945-459D-4D26-BE7C-0C7BAE688E67}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AB6B2A05-B134-47CF-B7C8-385A9C1F56BF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{ABBC4756-7293-4828-8A41-622FA1471AE1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{ABE136AC-4C12-4C18-B5CE-F2CCCAB64100}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{ABEB512A-8EC7-4E69-9970-E405F69D97D6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AC1FADC8-4582-4CB6-AAA2-3722B3CCD11B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AC41ACA5-0E15-47B9-A72A-5AC1DC87C392}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AD44CF31-03D0-476D-9D3B-AE7557EFF0C4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{ADC20C04-E1B7-49E5-BD70-84EA4AAA07B4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AE50F67A-E614-4176-A7C9-2B68DF25249C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AED925E9-4687-4C7B-81EA-131F4B617554}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AF270CF9-A65C-4FCC-91D7-6E5A971D0D1A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AF3A6219-2017-4FF8-92EC-27AAF6C864B4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{AFFA2E5C-66C9-4324-822F-AE5111858A3E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B0AF8B42-B6C2-4B84-862A-EBCD4F0071AD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B12CADC7-B7D4-40D8-8F28-CCA80FFC7A29}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B15A6A5F-80E6-46E4-9BAB-EE02EDD89071}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B191ADA3-040D-46AE-9780-06F9775D37B0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B1F97E93-A558-4F9B-BFD3-21D69E9C621E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B204B13F-4531-43C3-804D-426D7AE76563}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B214B21C-D024-4BC2-A665-1061F5FAF165}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B224A21C-89CD-4CE2-9250-467E56F5166D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B2A8308F-D493-4380-AA8C-A7F9719FA942}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B360E465-AA2D-4015-8D45-29183FA3F469}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B37B134B-7AE0-4ACD-97FC-2127D85FAD4A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B39B57BC-0BE3-4F73-83A5-52EDA68314D4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B3E50D45-2C32-4E44-A318-A4F122A08D94}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B3FB5CB4-42C5-4127-A0C8-E0444D7D444C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B3FCBAE4-F932-4988-AD5C-232041424C79}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B448F4A0-13D6-4A6D-A079-357DF370247B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B494EDF8-1DE9-4946-96E7-B2B2DC39B1F8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B5164647-FCF6-428B-8AC7-2606799DEEAE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B660BED3-DAFB-400B-B145-01ED83359D0D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B73BC5A0-9C71-4324-86B0-698C52AFFE0B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B76C7EA9-C664-44C6-A4FD-C61A160846CE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B7BB50AD-2482-4818-93FD-A810A7398F61}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B7FBB308-42BB-4EC9-AF6B-A84358951ABB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B84C80A2-4D2F-4586-AB9D-F2B12604C74E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B85096AE-53E0-4274-8F28-F3CABFE90FE6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{B9E6E1D5-D066-4614-B6CF-0DDFA24210D1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BA155FB9-F106-4A25-B698-CBA7705FA799}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BA76B7DC-AB94-4963-A2DB-D57C035E6168}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BAF34DD1-26FD-4074-9065-6A01218957D3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BB86DF5D-16F4-4B20-8875-BE7E4574A140}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BBF4AF99-AC72-41D7-B399-88AF1DC86FEA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BD3E7F85-83BD-42D0-99C0-48C2DFEE2155}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BD4DE5E0-E769-4905-8F97-1F0317231C2D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BD5F263D-141B-42FF-900D-2DE102659870}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BD61740F-7E52-4DB7-B13E-3AA3A47B8FC9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BD7A8A61-3F1B-459C-BD09-EFC668AB8398}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BE55A82C-4C1E-46B4-8C37-7CE74C67C77D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BE7B4D6D-3A08-4E8B-A807-85B48A7A25CB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BE83979A-E56C-42DB-8C7F-52AD230F409D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BEC45FDD-F513-4F14-9BB2-C4C893904117}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BF1EBBAA-A7A8-4A4B-95FF-E435CE1E194F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BF1FEDB9-2DE9-425D-AF03-6CF3E435C910}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BF5B8E66-411A-4421-9E72-189365C614B5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BFA29831-5381-478F-8EC9-D5C46F298A50}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BFC8A970-13C8-4F73-A078-96AAB18DC79C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{BFFBFDFB-2C68-4181-8630-998FBAA18124}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C00778C7-D49C-4456-B3CD-EAE56514BC51}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C0377578-ACB1-4A6A-A047-A670C512BDC1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C05779AA-3437-4BDB-A742-95A119C840C0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C1967999-C290-4AAB-987D-3634106DE0FF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C2974789-2EBB-44C7-ADC4-1F713349BA77}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C2DB5674-F3F0-4D2D-B09F-3D92D0EF2DBC}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C3B1001F-8D0E-4B3C-AFCB-AA2193FE7326}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C3B3B784-7B39-42F5-8F03-8E5DB8C59E77}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C400897B-4D3C-475A-9427-B65237D0EC8D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C4333C8C-2686-4515-BA1A-D43CE621D9C3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C493A071-0B84-4300-9CA7-C9AB44E000F1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C671316D-7BEE-4CC4-B5B5-DEFB23F3BCBE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C6846F1F-017B-4450-806D-5D36569B789A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C71EB8D2-5065-4EF3-B4E8-478E9D14E5B0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C7B8F8B6-9A1E-4008-ABD7-3DA997D79969}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C806EC2E-2031-4ADD-A44F-C87864FFDEA0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C85ECC9C-BD0D-48AC-9949-4B240CFBCCE6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C861A2BE-3141-44C0-BDEC-63B32167D20B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{C9C47483-0D0A-45C9-A3A2-FC4F452B74C7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CA19B33B-7B2C-4E6B-A493-E4C6C324341C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CA3B2D00-E054-4CF1-8ADC-D306C13EB71F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CA9EDDC3-F846-4980-B26B-097915836B13}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CB6B7885-C90D-436B-A91D-202FF9EF061C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CBD257FA-F81B-4DCB-8AE0-DE1A91EC8345}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CC766D49-416B-46EB-B763-B61D9D7F9B8A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CC811A8C-B8DB-4064-862E-19C33B1C7640}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CD16B8A4-BD0B-4C37-98D5-EC34E1C9D0BE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CDB256CC-9E41-4DC9-8492-63432AA6689B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CE6FA1FF-0354-4FE7-8807-DCB391AFDBF0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CEC718C5-B5D3-4200-9A08-C895442E0254}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CED38D4D-EF13-424C-B1A3-E521EFB2B8ED}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CF498426-9476-4B66-A185-9D09A791CEF1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CF4D6371-41DE-48DD-99FA-E263227A9EC1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CFB31B6A-2A9A-4868-B86E-C77EF82F0361}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{CFF474F9-A200-41DC-B2C9-74852F6BD80A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D02F8B19-9E53-4FE5-82C1-D930E5A95864}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D0926A59-222E-433F-814C-DE7755484827}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D0BFD25E-624A-4A3E-9315-8CB6DA3BB3A6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D140987D-C562-4C3C-B5E9-1B58291CF49D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D14DBE2C-3D2C-419E-BC5F-EADBB27EE808}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D1982580-5087-4DA0-B2F3-4C2BC3AE21D1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D1A4B8C0-7C6C-48F1-906E-5D08616B5B42}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D1C4D3DA-8C76-4080-B3E1-87BAFE3B0320}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D1D4FDED-C112-4F0D-8837-4480B603F33D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D1F4A11E-AD5C-4776-82DA-D6584EF8619C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D22D0192-AF24-44C0-AEA9-827305073205}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D3D7198A-4CC8-4340-9A91-2BED45C91D4E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D5A5B585-A615-4B7F-A9CB-195D3200428A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D65A6BD8-9A7C-4DBE-A24D-95DB98D9C249}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D681D410-49EB-4BC9-A064-22515DD0F8B6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D6E8E988-742A-4E16-9882-8D4244662937}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D6E91EAB-1FBC-4425-9FD4-1206446F1F57}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D721B2AA-D9E7-46EF-821B-AD64B40B0DA8}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D7E4D152-8EA6-40C6-AE8C-33363A8A8C41}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D7E9DFB8-EEF6-4463-ADC3-632861A955EE}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D7EB112A-C45B-46BB-A7EB-7F7C33C5FBE1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D8065BEC-BF0A-48F0-A223-DF2580671518}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D816D2A8-6D89-455F-950F-4A9804D0C20D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D86E6C22-DB06-4EEF-80AA-1EE693A09EA0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D960E453-6392-442C-BCC8-6E288953611E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{D9EFC153-A319-4558-B7EF-50D7E84D9204}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DAA403DA-81C4-46A1-B0E2-337A5CFC0C31}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DB905B68-F5C4-4789-91A2-2E57B9386BB3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DBA8DAE2-6D75-4641-838E-912F4870BF26}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DBF7315B-8891-416F-A044-E4C1B72FB252}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DC02640F-80D3-4100-B730-C379F203C2D7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DC056B14-A6CC-4713-8135-31701E19D11D}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DC10B33D-BAA8-435E-B0D8-628F60D55D54}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DC22F732-1A55-45BF-B067-1F4A15F81B32}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DC282FFF-9AFC-49A3-A4C3-42E10343347F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DC30AAD3-6860-40DE-97A9-DA5C82A54431}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DC3CC512-14D8-4CA6-ACBD-738EEE3B1A64}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DC6654B3-215B-4C0B-881E-8D27B9DC61F9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DD62ACE7-6D31-4A22-AD17-ED12D900D196}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DE86631C-D25E-48DC-A475-5905AB9CAF5E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{DF51DDAE-B5A6-4254-9B05-16A48DD89B07}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E0372AED-1C07-41FA-9795-5EC8170DEF6E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E0CA1D73-9398-48CF-A8CA-EE56AA83BFCC}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E0D7917D-620D-41BF-BEC7-5878BF8D68F9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E1379C28-8002-4BBD-A65C-66DD5B67955B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E14C7C73-D588-4569-907B-F617B718E931}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E1502A23-3465-4AE6-9E19-555C5DDF802E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E19CAF69-68E4-41C4-9770-CBE6C0DDD5AA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E1BA74AA-FAE0-4321-9454-16E04D8245F2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E1F539AD-A6D5-407D-8371-BE7D2351FADD}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E232CC84-F138-4B7D-B215-3FAB1F63B5AC}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E26556C7-7A10-455D-9C12-1496FFB84429}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E30707B4-6A62-4992-9E26-A56C2425E91C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E32C2397-B01A-4F40-86A1-7FF13CD6940F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E3395D06-AEE2-47F0-8520-C9330DEB9CE7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E3627AB9-2DDC-40FB-B85B-111FC2273070}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E39D7FCE-6824-4467-9837-753671447926}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E3BA9E25-0304-473F-94F2-454E59A43C35}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E4238C67-3A9A-4CA9-ADEC-F51842735750}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E47EBD63-C725-410F-A7AD-25140590A509}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E4C90867-2FFF-4DE5-AE8C-9B093644DE37}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E527E9DD-DDAE-432B-BC31-178E29B3F3D0}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E5D40EBE-56CE-4970-A1F4-16E309A8FB40}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E6286C09-2AE8-40EC-9762-AE31291CD5D5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E73390F5-56C7-475C-9D01-533557994B6B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E764F8D3-335B-4D41-8CE3-3D13EA626149}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E7C83FB5-D799-4E98-A92A-613E423965B9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E8C96EDB-DA95-4B22-AE20-2F67346F4CAB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{E94F8EC1-1556-46CD-8E96-98662780F0A7}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EA7B7B83-02D7-40F3-A649-606C7ABE53C1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EB6B126F-F8BC-490A-BE3B-5F73E0D5BC90}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EC031171-AD6E-4792-B545-84597DD54F0F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{ECAFC547-333C-4A69-8C25-4CB6690F5819}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{ED3F3F83-B4BE-4751-8CAA-439CD55772D2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EDCA8C8D-C135-493D-A531-8C87F83FE1D6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EDD74E21-BB60-43E9-B148-929991AA1D46}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EDD7CBD8-7C29-46C5-9577-49DDBD1232C5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EDFDB154-3F6A-4EAD-BBCC-527528767432}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EE072CF7-914D-4024-8FAE-89A68FA27D88}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EE519AFE-30C6-4CE1-A2D3-FE8ABD844CEB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EEA7CAD4-CCC7-4744-8482-57030EDF8B83}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EF2E8461-846D-4FEA-97A0-F3BEBB0DA376}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EF369179-434B-4D13-8704-C7165ADDED59}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EF475C2A-02E2-488B-8EFD-B8FF0F327F0E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EF97554E-415B-47DD-9C31-127406E09836}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{EFABA54F-9B44-4C57-8AC0-A0B406A622C2}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F000CC80-6C23-4D9A-9CBC-29B9F3F9019F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F00F3FFB-6FB6-4630-9DA9-1D437F7ACA8B}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F018664F-C7AC-4047-B8F6-482403F6C9F1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F0224249-23C5-4985-812B-B8F9E94ADB31}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F0697091-3F88-4033-B34D-05EA404045C6}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F086C302-D78F-4413-A6B5-995A1860CD4F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F0B3D232-34D4-4387-A887-2DE0FF9916F5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F1414CFF-539B-4337-B8E1-4AC0AD3ADD77}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F1CE683C-F688-494B-B570-24C3F613BF09}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F1DA47DF-6015-43F5-BF85-DFCCAB002AC4}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F1FA4A95-0051-4128-828E-613FA64C71E1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F2AC7C2B-0818-4BCE-867F-59C19E8E4630}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F415B8C5-6F30-4FC5-A366-A97420358783}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F44DB3AC-9870-4218-B115-101B53D22B11}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F4DCD5E7-AB3E-44EC-8AD8-5962C34CE830}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F4F4266C-BAF3-4A97-9251-F35D5CD4FD4C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F5E197E4-7362-4180-B54E-1C57BB337135}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F67280DB-0060-4FCE-B6D6-628EEBF5E828}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F6998AA3-BDD3-4574-9503-42A42490D2CB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F6DAE6D7-DD41-4C7E-985E-F637312F59FF}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F6ED1C4F-70DB-4CEB-BCA6-FA07107CEEA5}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F8CB3221-F14A-46BF-925F-E13E76D3B3D9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F8FD5899-DE64-43FD-8D8E-41E649EE6118}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F971F409-4A29-44A2-A8AD-8E8B2B2B54EC}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F9AEB635-1C9C-48FB-B07D-E5D187FC80A3}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F9CC618B-5FF9-4DEE-B55E-6EE12493232A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{F9DBA80D-50DF-484C-9250-607B48F92EEB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FA179612-8EEE-49BC-A44C-564A27B6A961}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FA6746C1-9922-463C-8831-C54343A9A397}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FA7BBA01-05D1-4843-AB47-ED1C830E7FFB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FB7D234D-E537-4664-8951-39AFD36AABA1}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FBC129AC-C778-4B21-928F-E6E3DEAC4CBA}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FBD60E46-9DD9-40FD-9C22-9452B9F0EF3E}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FC013A30-B068-4302-A75B-5906E6E55296}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FC1BB4F7-8B01-4C69-BC5D-969880973748}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FC5A96D2-3346-467E-837B-37ADE8944B67}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FD33D752-D28D-47B6-AA3A-0D5076D42C5C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FD503ED8-00F3-466F-B347-085BCF6271BB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FDA46E90-40C4-40A1-A5F6-E7E4EE8F37EB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FE0358AA-7AC2-406C-BA68-ACA32D312A81}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FE0861A5-139F-4958-8478-64ABD12B462F}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FE1DBFAC-2308-4160-8523-41C7A1E0FE5C}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FEADF67B-0755-4835-B592-23A4030CEFCB}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FEF13257-E335-4261-9B98-DF5F0BDA2207}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FF4EB6C1-0C18-45DB-8E84-D23FEF55D53A}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FFAAA8F0-007C-420C-9878-8E836F8C2FA9}
Successfully deleted: [Empty Folder] C:\Users\Ryan2011\appdata\local\{FFEAA78A-637C-4FC6-939A-DAFD02883856}
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 05/15/2017 at 14:54:05.75
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • 0

#7
Lyanheart

Lyanheart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 5/15/17
Scan Time: 2:56 PM
Logfile: 
Administrator: Yes
 
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.0
Update Package Version: 1.0.1946
License: Premium
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Ryan2011-PC\Ryan2011
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 345064
Time Elapsed: 4 min, 14 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)

  • 0

#8
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,087 posts
Hello,

Click start> search and type cmd, right click on the returned cmd.exe and select "run as administrator" at the prompt>>> type or (copy paste) the text in the code box below into the command prompt window
echo > 0 & tasklist /v >> 0 & net start >> 0 & notepad 0
press enter on your keyboard.
A log file in note pad will be created on the desktop.
Post all of the notepad outcome in your next reply.
  • 0

#9
Lyanheart

Lyanheart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
ECHO is on.
 
Image Name                     PID Session Name        Session#    Mem Usage Status          User Name                                              CPU Time Window Title                                                            
========================= ======== ================ =========== ============ =============== ================================================== ============ ========================================================================
System Idle Process              0 Services                   0         24 K Unknown         NT AUTHORITY\SYSTEM                                     0:17:33 N/A                                                                     
System                           4 Services                   0      1,660 K Unknown         N/A                                                     0:00:19 N/A                                                                     
smss.exe                       300 Services                   0      1,140 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
csrss.exe                      440 Services                   0      4,244 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:02 N/A                                                                     
wininit.exe                    484 Services                   0      4,504 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
csrss.exe                      508 Console                    1     17,200 K Running         NT AUTHORITY\SYSTEM                                     0:00:03 N/A                                                                     
services.exe                   556 Services                   0      9,784 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
winlogon.exe                   580 Console                    1      7,168 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
lsass.exe                      592 Services                   0     15,336 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:05 N/A                                                                     
lsm.exe                        604 Services                   0      4,324 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
svchost.exe                    716 Services                   0      9,788 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:02 N/A                                                                     
svchost.exe                    796 Services                   0      8,580 K Unknown         NT AUTHORITY\NETWORK SERVICE                            0:00:00 N/A                                                                     
svchost.exe                    892 Services                   0     22,716 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
svchost.exe                    924 Services                   0    135,068 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:16 N/A                                                                     
svchost.exe                    964 Services                   0     18,256 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
svchost.exe                    996 Services                   0     37,196 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:01 N/A                                                                     
audiodg.exe                    332 Services                   0     19,004 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
svchost.exe                    452 Services                   0      6,204 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
svchost.exe                    312 Services                   0     15,176 K Unknown         NT AUTHORITY\NETWORK SERVICE                            0:00:01 N/A                                                                     
svchost.exe                   1160 Services                   0     16,944 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:01 N/A                                                                     
spoolsv.exe                   1280 Services                   0     18,872 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
taskhost.exe                  1452 Console                    1     17,000 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 MCI command handling window                                             
dwm.exe                       1500 Console                    1     33,244 K Running         Ryan2011-PC\Ryan2011                                    0:00:07 DWM Notification Window                                                 
explorer.exe                  1548 Console                    1     54,924 K Running         Ryan2011-PC\Ryan2011                                    0:00:05 N/A                                                                     
svchost.exe                   1588 Services                   0     10,760 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
dlbkcoms.exe                  1616 Services                   0      4,920 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
svchost.exe                   1680 Services                   0     13,416 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
svchost.exe                   1760 Services                   0      3,676 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
PDFProFiltSrvPP.exe           1872 Services                   0      3,744 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
RAVCpl64.exe                  2016 Console                    1     10,392 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 Realtek HD Audio CPL for Vista                                          
hkcmd.exe                     1044 Console                    1     10,528 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
igfxpers.exe                  1132 Console                    1      8,912 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 PersistWndName                                                          
mbamtray.exe                  1720 Console                    1     18,224 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 mbamtray                                                                
Plex Media Server.exe         1408 Console                    1     19,588 K Running         Ryan2011-PC\Ryan2011                                    0:00:01 N/A                                                                     
ISUSPM.exe                    2032 Console                    1      6,700 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
DropboxUpdate.exe             1104 Console                    1      2,968 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 {2D905E07-FC38-4b89-83E1-931D3630937F}                                  
Dropbox.exe                   1048 Console                    1    142,420 K Running         Ryan2011-PC\Ryan2011                                    0:00:10 Press enter to open the Dropbox menu                                    
svchost.exe                   2220 Services                   0      3,652 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
IAStorIcon.exe                2248 Console                    1     21,672 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
pptd40nt.exe                  2360 Console                    1      4,840 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 ScanSoft PaperPort Print Driver                                         
pdfPro5Hook.exe               2368 Console                    1      5,188 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 Pdf Professional 5.0.Wnd                                                
BrStMonW.exe                  2396 Console                    1     10,860 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 Brother Status Monitor                                                  
svchost.exe                   2440 Services                   0      7,608 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
BrCtrlCntr.exe                2464 Console                    1      7,456 K Unknown         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
WLIDSVC.EXE                   2500 Services                   0     16,208 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
wmpnetwk.exe                  2600 Services                   0      5,724 K Unknown         NT AUTHORITY\NETWORK SERVICE                            0:00:00 N/A                                                                     
SearchIndexer.exe             2660 Services                   0     24,440 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:01 N/A                                                                     
MBAMService.exe               2760 Services                   0    333,712 K Unknown         NT AUTHORITY\SYSTEM                                     0:01:25 N/A                                                                     
WLIDSVCM.EXE                  2840 Services                   0      3,380 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
BrCcUxSys.exe                 2300 Console                    1      6,576 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 ControlCenter4                                                          
Dropbox.exe                   3160 Console                    1      7,764 K Unknown         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
BrYNSvc.exe                   3308 Services                   0      8,816 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
WUDFHost.exe                  3352 Services                   0      6,396 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
PlexScriptHost.exe            3940 Console                    1     34,196 K Running         Ryan2011-PC\Ryan2011                                    0:00:08 C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe        
conhost.exe                   2376 Console                    1      4,680 K Unknown         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
svchost.exe                   3276 Services                   0     15,560 K Unknown         NT AUTHORITY\LOCAL SERVICE                              0:00:00 N/A                                                                     
WmiPrvSE.exe                  4456 Services                   0      6,048 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
PlexDlnaServer.exe            4584 Console                    1      9,252 K Unknown         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
dllhost.exe                   4112 Services                   0      7,216 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
taskeng.exe                   3844 Console                    1      6,052 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 TaskEng - Task Scheduler Engine Process                                 
WR_Tray_Icon.exe              3272 Console                    1      1,120 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 WR Tray Icon                                                            
IAStorDataMgrSvc.exe          4084 Services                   0     15,628 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
wuauclt.exe                   5940 Console                    1      6,872 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 Windows Update Taskbar Notification                                     
chrome.exe                    6080 Console                    1    108,304 K Running         Ryan2011-PC\Ryan2011                                    0:00:11 PC recently and suddenly became very sluggish and unresonsive across a -
chrome.exe                    6064 Console                    1      5,344 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
chrome.exe                    3472 Console                    1      6,216 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
chrome.exe                    2416 Console                    1     69,540 K Not Responding  Ryan2011-PC\Ryan2011                                    0:00:06 AngleHiddenWindow                                                       
chrome.exe                    2584 Console                    1     29,116 K Unknown         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
taskeng.exe                   5332 Console                    1      6,264 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 TaskEng - Task Scheduler Engine Process                                 
chrome.exe                    1676 Console                    1     86,620 K Unknown         Ryan2011-PC\Ryan2011                                    0:00:05 N/A                                                                     
cmd.exe                       3624 Console                    1      2,956 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 tasklist  /v                                                            
conhost.exe                   2012 Console                    1      5,460 K Running         Ryan2011-PC\Ryan2011                                    0:00:00 OleMainThreadWndName                                                    
mbupdatr.exe                  5172 Services                   0      5,928 K Unknown         NT AUTHORITY\SYSTEM                                     0:00:00 N/A                                                                     
tasklist.exe                  5388 Console                    1      6,456 K Unknown         Ryan2011-PC\Ryan2011                                    0:00:00 N/A                                                                     
WmiPrvSE.exe                  5988 Services                   0      6,524 K Unknown         NT AUTHORITY\NETWORK SERVICE                            0:00:00 N/A                                                                     
These Windows services are started:
 
   Application Experience
   Application Information
   Background Intelligent Transfer Service
   Base Filtering Engine
   BrYNSvc
   CNG Key Isolation
   COM+ Event System
   Computer Browser
   Cryptographic Services
   DCOM Server Process Launcher
   Desktop Window Manager Session Manager
   DHCP Client
   Diagnostic Policy Service
   Diagnostic Service Host
   Diagnostic System Host
   Diagnostics Tracking Service
   Distributed Link Tracking Client
   dlbk_device
   DNS Client
   Extensible Authentication Protocol
   Function Discovery Provider Host
   Function Discovery Resource Publication
   Group Policy Client
   HomeGroup Listener
   HomeGroup Provider
   Human Interface Device Access
   IKE and AuthIP IPsec Keying Modules
   Intel® Rapid Storage Technology
   IP Helper
   Malwarebytes Service
   Multimedia Class Scheduler
   Net Driver HPZ12
   Network Connections
   Network List Service
   Network Location Awareness
   Network Store Interface Service
   PDFProFiltSrvPP
   Peer Name Resolution Protocol
   Peer Networking Grouping
   Peer Networking Identity Manager
   Plug and Play
   Pml Driver HPZ12
   Portable Device Enumerator Service
   Power
   Print Spooler
   Remote Desktop Services
   Remote Procedure Call (RPC)
   RPC Endpoint Mapper
   Security Accounts Manager
   Security Center
   Server
   Shell Hardware Detection
   SSDP Discovery
   Superfetch
   System Event Notification Service
   Task Scheduler
   TCP/IP NetBIOS Helper
   Themes
   UPnP Device Host
   User Profile Service
   Windows Audio
   Windows Audio Endpoint Builder
   Windows Driver Foundation - User-mode Driver Framework
   Windows Event Log
   Windows Firewall
   Windows Font Cache Service
   Windows Image Acquisition (WIA)
   Windows Live ID Sign-in Assistant
   Windows Management Instrumentation
   Windows Media Player Network Sharing Service
   Windows Search
   Windows Update
   WinHTTP Web Proxy Auto-Discovery Service
   WLAN AutoConfig
   Workstation
   WWAN AutoConfig
 
The command completed successfully.

  • 0

#10
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,087 posts
Hows the computer doing right now ?
  • 0

#11
Lyanheart

Lyanheart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts

Everything has been doing fine today. As far as I remember, even last Friday before I left for the weekend everything seemed to be working alright.


  • 0

#12
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,087 posts
Hello,

Everything looks ok here too.

We need to remove the tools we used and then close the topic.

The following procedures will implement some cleanup procedures to remove these tools. It will also reset your System Restore by flushing out previous restore points and create a new restore point. It will also remove all the backups our tools may have made.
Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).

Why we need to remove some of our tools:
Some of the tools we have used to clean your computer were made by fellow malware fighters and are very powerful and if used incorrectly or at the wronge time can make the computer an expensive paper weight. They are updated all the time and some of them more than once a day so by the time you are ready to use them again they will already be outdated.


Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the 51a5ce45263de-delfix.png icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run.
  • The program will run for a few seconds and display a notepad report.
    Paste it for my review.

  • 0

#13
Lyanheart

Lyanheart

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
# DelFix v1.010 - Logfile created 15/05/2017 at 15:41:48
# Updated 26/04/2015 by Xplode
# Username : Ryan2011 - RYAN2011-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
 
~ Removing disinfection tools ...
 
Deleted : C:\_OTL
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\RegBackup
Deleted : C:\Users\Ryan2011\Desktop\JRT.txt
Deleted : C:\Users\Ryan2011\Downloads\adwcleaner_6.046.exe
Deleted : C:\Users\Ryan2011\Downloads\avenger.zip
Deleted : C:\Users\Ryan2011\Downloads\OTL.exe
Deleted : C:\Users\Ryan2011\Downloads\tdsskiller.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR
 
~ Cleaning system restore ...
 
Deleted : RP #645 [Scheduled Checkpoint | 05/01/2017 21:26:39]
Deleted : RP #646 [Scheduled Checkpoint | 05/09/2017 04:00:06]
Deleted : RP #647 [Removed Samsung Kies | 05/10/2017 14:07:08]
Deleted : RP #648 [Removed Virtual Pool 4 Demo | 05/10/2017 14:11:05]
Deleted : RP #649 [Restore Point Created by FRST | 05/15/2017 12:40:12]
 
New restore point created !
 
~ Resetting system settings ... OK
 
########## - EOF - ##########

  • 0

#14
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,087 posts
Thank- You !

You usually get infected because your security settings are too low.

Here are a number of recommendations that will help tighten them, and which will contribute to making you a less likely victim:

Safe Computing Practices please read Here


Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Thanks
Joe :)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP