Hi, I have been experiencing pretty werid things,for example the search engine keeps changing to myluckysite and sometimes I find some random apps shortcuts,and the internet is sometimes very slow on the pc only,i also find unknown apps on task manager like pc cleanplus and T0Yz&0qCVp.exe.the only browser I have installed right now is Microsoft edge and internet explorer. so anyway I scanned it with malwarebyte anti rootkit, and it found like 2000+ threats and the tool keeps lagging after reaching 2000 or more,anyway I scanned with farbar and here are the results:
Ran by hdz (administrator) on HDZZ (14-06-2017 16:22:38)
Running from C:\Users\hdz\Downloads
Loaded Profiles: hdz & (Available Profiles: defaultuser0 & hdz)
Platform: Microsoft Windows 10 Pro Version 1703 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x86__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.425.10010.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.1602.0_x86__8wekyb3d8bbwe\Calculator.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x86__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\System32\osk.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
HKU\S-1-5-21-2863771085-710865549-2862127350-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [515072 2017-03-18] (Microsoft Corporation)
HKLM\...\Providers\quvbwdhx: C:\Program Files\Jujalyclartion Launcher\local32spl.dll
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\hdz\AppData\Local\MEGAsync\ShellExtX32.dll -> No File
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\hdz\AppData\Local\MEGAsync\ShellExtX32.dll -> No File
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\hdz\AppData\Local\MEGAsync\ShellExtX32.dll -> No File
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Users\hdz\AppData\Local\Temp\Rar$EXa0.501\IDMShellExt.dll [2015-08-14] (Tonec Inc.)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x86.dll [2016-10-25] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ultra Hal Assistant 6 Startup.lnk [2017-05-20]
ShortcutTarget: Ultra Hal Assistant 6 Startup.lnk -> C:\Program Files\Zabaware\Ultra Hal Assistant 6\HalAsst.exe (Zabaware)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Zabaware Reader Startup.lnk [2017-05-20]
ShortcutTarget: Zabaware Reader Startup.lnk -> C:\Program Files\Zabaware\Reader 2\ZabaReader.exe (Zabaware, Inc.)
InternetURL: C:\Users\hdz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conros.com.url -> URL: C:\Users\hdz\AppData\Roaming\csjtl.exe
GroupPolicy: Restriction ? <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
Tcpip\Parameters: [DhcpNameServer] 1.1.1.2 185.116.116.155 8.8.8.8 192.168.1.1
Tcpip\..\Interfaces\{5c6ffd9f-dc25-4c04-8ce6-25725dc808f3}: [DhcpNameServer] 1.1.1.2 185.116.116.155 8.8.8.8 192.168.1.1
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=1495617312&z=7c5b68a31f77ad5e60213b0g3z1t7wfqagfm8cdg4g&from=che0812&uid=ST9320325AS_6VDE8D5H
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&ts=1495617312&z=7c5b68a31f77ad5e60213b0g3z1t7wfqagfm8cdg4g&from=che0812&uid=ST9320325AS_6VDE8D5H&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1495617312&z=7c5b68a31f77ad5e60213b0g3z1t7wfqagfm8cdg4g&from=che0812&uid=ST9320325AS_6VDE8D5H
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&ts=1495617312&z=7c5b68a31f77ad5e60213b0g3z1t7wfqagfm8cdg4g&from=che0812&uid=ST9320325AS_6VDE8D5H&q={searchTerms}
HKU\S-1-5-21-2863771085-710865549-2862127350-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1495617312&z=7c5b68a31f77ad5e60213b0g3z1t7wfqagfm8cdg4g&from=che0812&uid=ST9320325AS_6VDE8D5H
HKU\S-1-5-21-2863771085-710865549-2862127350-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_savemygame_17_11_dopc¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dlb%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0C0ByBtD0D0AyDyByCyDzz0A0C0DyDtN0D0Tzu0StCzytDtAtN1L2XzutAtFtByCtFtBtFyDtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCzyyBtCzytCzyyCtGtB0AyBtBtGtBtB0CzytGyE0B0EtCtGtDyB0AyDyByEzz0BtDtDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0C0B0FtBzz0FyEtGyByE0ByCtGyEzyyE0CtGzz0C0A0FtGzy0DyBtC0CtB0A0A0E0ByDtD2QtN0A0LzuyE%26cr%3D1091661411%26a%3Dwny_savemygame_17_11_dopc%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=1495617312&z=7c5b68a31f77ad5e60213b0g3z1t7wfqagfm8cdg4g&from=che0812&uid=ST9320325AS_6VDE8D5H
HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_savemygame_17_11_dopc¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dlb%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0C0ByBtD0D0AyDyByCyDzz0A0C0DyDtN0D0Tzu0StCzytDtAtN1L2XzutAtFtByCtFtBtFyDtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCzyyBtCzytCzyyCtGtB0AyBtBtGtBtB0CzytGyE0B0EtCtGtDyB0AyDyByEzz0BtDtDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0C0B0FtBzz0FyEtGyByE0ByCtGyEzyyE0CtGzz0C0A0FtGzy0DyBtC0CtB0A0A0E0ByDtD2QtN0A0LzuyE%26cr%3D1091661411%26a%3Dwny_savemygame_17_11_dopc%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro
SearchScopes: HKU\S-1-5-21-2863771085-710865549-2862127350-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_savemygame_17_11_dopc¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dlb%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0C0ByBtD0D0AyDyByCyDzz0A0C0DyDtN0D0Tzu0StCzytDtAtN1L2XzutAtFtByCtFtBtFyDtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCzyyBtCzytCzyyCtGtB0AyBtBtGtBtB0CzytGyE0B0EtCtGtDyB0AyDyByEzz0BtDtDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0C0B0FtBzz0FyEtGyByE0ByCtGyEzyyE0CtGzz0C0A0FtGzy0DyBtC0CtB0A0A0E0ByDtD2QtN0A0LzuyE%26cr%3D1091661411%26a%3Dwny_savemygame_17_11_dopc%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2863771085-710865549-2862127350-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_savemygame_17_11_dopc¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dlb%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0C0ByBtD0D0AyDyByCyDzz0A0C0DyDtN0D0Tzu0StCzytDtAtN1L2XzutAtFtByCtFtBtFyDtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCzyyBtCzytCzyyCtGtB0AyBtBtGtBtB0CzytGyE0B0EtCtGtDyB0AyDyByEzz0BtDtDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0C0B0FtBzz0FyEtGyByE0ByCtGyEzyyE0CtGzz0C0A0FtGzy0DyBtC0CtB0A0A0E0ByDtD2QtN0A0LzuyE%26cr%3D1091661411%26a%3Dwny_savemygame_17_11_dopc%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_savemygame_17_11_dopc¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dlb%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0C0ByBtD0D0AyDyByCyDzz0A0C0DyDtN0D0Tzu0StCzytDtAtN1L2XzutAtFtByCtFtBtFyDtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCzyyBtCzytCzyyCtGtB0AyBtBtGtBtB0CzytGyE0B0EtCtGtDyB0AyDyByEzz0BtDtDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0C0B0FtBzz0FyEtGyByE0ByCtGyEzyyE0CtGzz0C0A0FtGzy0DyBtC0CtB0A0A0E0ByDtD2QtN0A0LzuyE%26cr%3D1091661411%26a%3Dwny_savemygame_17_11_dopc%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_savemygame_17_11_dopc¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dlb%26pa%3Dwinyahoo%26cd%3D2XzuyEtN2Y1L1Qzuzy0C0ByBtD0D0AyDyByCyDzz0A0C0DyDtN0D0Tzu0StCzytDtAtN1L2XzutAtFtByCtFtBtFyDtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCzyyBtCzytCzyyCtGtB0AyBtBtGtBtB0CzytGyE0B0EtCtGtDyB0AyDyByEzz0BtDtDyEtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0C0B0FtBzz0FyEtGyByE0ByCtGyEzyyE0CtGzz0C0A0FtGzy0DyBtC0CtB0A0A0E0ByDtD2QtN0A0LzuyE%26cr%3D1091661411%26a%3Dwny_savemygame_17_11_dopc%26os_ver%3D10.0%26os%3DWindows%2B10%2BPro&p={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Users\hdz\AppData\Local\Temp\Rar$EXa0.501\IDMIECC.dll [2016-12-10] (Internet Download Manager, Tonec Inc.)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-03-19] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-19] (Oracle Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
======
Edge HomeButtonPage: HKU\S-1-5-21-2863771085-710865549-2862127350-1001 -> hxxp://www.ourluckysites.com/?type=hp&ts=1495617312&z=7c5b68a31f77ad5e60213b0g3z1t7wfqagfm8cdg4g&from=che0812&uid=ST9320325AS_6VDE8D5H
Edge Extension: (No Name) -> IDMIntegrationModule_5B7ACC0AB2EB44E3AC0E4A451EA0DB8E => C:\Program Files\Internet Download Manager [2017-06-14]
========
FF DefaultProfile: 7y3wvght.default
FF ProfilePath: C:\Users\hdz\AppData\Roaming\Mozilla\Firefox\Profiles\7y3wvght.default [2017-04-27]
FF Homepage: Mozilla\Firefox\Profiles\7y3wvght.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/
FF NetworkProxy: Mozilla\Firefox\Profiles\7y3wvght.default -> type",
FF ProfilePath: C:\Users\hdz\AppData\Roaming\Firefox\Firefox\Profiles\7y3wvght.default [2017-05-27]
FF SearchPlugin: C:\Users\hdz\AppData\Roaming\Firefox\Firefox\Profiles\7y3wvght.default\searchplugins\startsearch.xml [2017-05-27]
FF HKU\S-1-5-21-2863771085-710865549-2862127350-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\hdz\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\hdz\AppData\Roaming\IDM\idmmzcc5 [2017-06-14] [not signed]
FF HKU\S-1-5-21-2863771085-710865549-2862127350-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\hdz\AppData\Local\Temp\Rar$EXa0.501\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Users\hdz\AppData\Local\Temp\Rar$EXa0.501\idmmzcc2.xpi [2017-01-26]
FF HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\hdz\AppData\Roaming\IDM\idmmzcc5
FF HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\hdz\AppData\Local\Temp\Rar$EXa0.501\idmmzcc2.xpi
FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-19] (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-03-27] (Adobe Systems)
FF Plugin HKU\S-1-5-21-2863771085-710865549-2862127350-1001: @nsroblox.roblox.com/launcher -> C:\Users\hdz\AppData\Local\Roblox\Versions\version-88b966c853f84435\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-2863771085-710865549-2862127350-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\hdz\AppData\Local\Roblox\Versions\version-88b966c853f84435\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @nsroblox.roblox.com/launcher -> C:\Users\hdz\AppData\Local\Roblox\Versions\version-88b966c853f84435\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @nsroblox.roblox.com/launcher64 -> C:\Users\hdz\AppData\Local\Roblox\Versions\version-88b966c853f84435\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
=======
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Users\hdz\AppData\Local\Temp\Rar$EXa0.501\IDMGCExt.crx [2017-04-26]
StartMenuInternet: Google Chrome - Chrome.exe
HKU\S-1-5-21-2863771085-710865549-2862127350-1001\...\StartMenuInternet\ChromeHTML: -> C:\Program Files\Bangtony\Application\chrome.exe <==== ATTENTION
HKU\S-1-5-21-2863771085-710865549-2862127350-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartMenuInternet\ChromeHTML: -> C:\Program Files\Bangtony\Application\chrome.exe <==== ATTENTION
R2 AGSService; C:\Program Files\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
S3 cphs; C:\WINDOWS\system32\IntelCpHeciSvc.exe [300120 2017-03-10] (Intel Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [263936 2015-07-03] (Realtek Semiconductor)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2545848 2017-03-18] (Microsoft Corporation)
R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-12-03] (DEVGURU Co., LTD.)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [227504 2016-04-28] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [265352 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [82488 2017-03-18] (Microsoft Corporation)
R2 WinSAPSvc; C:\Users\hdz\AppData\Roaming\WinSAPSvc\WinSAP.dll [1887232 2017-05-17] () [File not signed] <==== ATTENTION
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [109184 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae.sys [59904 2017-03-22] ()
R3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [94936 2017-06-14] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [170200 2017-06-14] (Malwarebytes)
R3 RSPCIESTOR; C:\WINDOWS\system32\DRIVERS\RtsPStor.sys [256616 2012-03-29] (Realtek Semiconductor Corp.)
S3 rt640x86; C:\WINDOWS\System32\drivers\rt640x86.sys [504832 2017-03-18] (Realtek )
R3 rtwlane_13; C:\WINDOWS\System32\drivers\rtwlane_13.sys [3182592 2017-03-18] (Realtek Semiconductor Corporation )
R1 SCDEmu; C:\WINDOWS\system32\Drivers\SCDEmu.sys [124304 2017-02-02] (Power Software Ltd)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [44216 2016-04-28] (Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [147072 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 ssudserd; C:\WINDOWS\system32\DRIVERS\ssudserd.sys [147072 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [23040 2016-04-21] (The OpenVPN Project)
S3 taphss6; C:\WINDOWS\System32\drivers\taphss6.sys [36944 2017-05-16] (Anchorfree Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [37464 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [243104 2017-03-18] (Microsoft Corporation)
S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [119952 2016-07-15] (MBB)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [96672 2017-03-18] (Microsoft Corporation)
R3 WUDFWpdMtp; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [160256 2017-03-18] (Microsoft Corporation)
S3 MBAMFarflt; \??\C:\WINDOWS\system32\drivers\farflt.sys [X]
S3 MBAMWebProtection; \??\C:\WINDOWS\system32\drivers\mwac.sys [X]
U2 snare; no ImagePath
==================== One Month Created files and folders ========
2017-06-14 14:47 - 2017-06-14 14:47 - 00262936 _____ (Kaspersky Lab, Yury Parshin) C:\WINDOWS\system32\Drivers\42713748.sys
2017-06-14 14:44 - 2017-06-14 14:44 - 00262936 ____N (Kaspersky Lab, Yury Parshin) C:\WINDOWS\system32\Drivers\61251314.sys
2017-06-14 13:49 - 2017-06-14 13:50 - 00028860 _____ C:\Users\hdz\Downloads\Addition.txt
2017-06-14 13:46 - 2017-06-14 13:47 - 01777152 _____ (Farbar) C:\Users\hdz\Downloads\FRST.exe
2017-06-14 05:07 - 2017-06-14 16:22 - 00000000 ____D C:\FRST
2017-06-14 03:57 - 2017-06-14 14:48 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-06-14 03:57 - 2017-06-14 14:48 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-06-14 03:57 - 2017-06-14 03:57 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-14 03:54 - 2017-06-14 14:48 - 00094936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-06-14 03:54 - 2017-06-14 14:35 - 00000000 ____D C:\Users\hdz\Desktop\mbar
2017-06-14 03:51 - 2017-06-14 03:51 - 00001145 _____ C:\Users\hdz\Desktop\Internet Download Manager.lnk
2017-06-14 03:49 - 2017-06-14 03:51 - 00000000 ____D C:\Users\hdz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2017-06-14 03:49 - 2017-06-14 03:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2017-06-14 03:48 - 2017-06-14 03:54 - 16563352 _____ (Malwarebytes Corp.) C:\Users\hdz\Downloads\mbar-1.09.3.1001.exe
2017-06-14 03:46 - 2017-06-14 03:51 - 00930816 _____ C:\Users\hdz\AppData\Local\test_db_cara.db
2017-06-14 03:46 - 2017-06-14 03:46 - 00140800 _____ C:\Users\hdz\AppData\Local\installer.dat
2017-06-14 03:46 - 2017-06-14 03:46 - 00011568 _____ C:\Users\hdz\AppData\Local\InstallationConfiguration.xml
2017-06-14 03:45 - 2017-06-14 03:51 - 07160560 _____ (Tonec Inc.) C:\Users\hdz\Downloads\idman628build7.exe
2017-06-14 03:43 - 2017-06-14 15:10 - 00000000 ____D C:\Users\hdz\AppData\Roaming\IDM
2017-06-14 03:43 - 2017-06-14 03:53 - 00000000 ____D C:\Users\hdz\AppData\Roaming\DMCache
2017-06-14 03:43 - 2017-06-14 03:43 - 00000000 ____D C:\ProgramData\IDM
2017-06-14 03:40 - 2017-06-14 03:40 - 00117760 _____ C:\WINDOWS\Manager.exe
2017-06-13 23:30 - 2017-06-03 12:36 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-06-13 23:30 - 2017-06-03 12:33 - 00095640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-06-13 23:30 - 2017-06-03 12:25 - 00177056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-06-13 23:30 - 2017-06-03 12:24 - 00249016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-06-13 23:30 - 2017-06-03 12:20 - 02086304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-06-13 23:30 - 2017-06-03 12:11 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-06-13 23:30 - 2017-06-03 12:09 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-06-13 23:30 - 2017-06-03 12:08 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-06-13 23:30 - 2017-06-03 12:07 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-06-13 23:30 - 2017-06-03 12:07 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-06-13 23:30 - 2017-06-03 12:06 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-06-13 23:30 - 2017-06-03 12:04 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-06-13 23:30 - 2017-06-03 12:03 - 19336192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-06-13 23:30 - 2017-06-03 12:03 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-06-13 23:30 - 2017-06-03 12:00 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-06-13 23:30 - 2017-06-03 11:59 - 02672128 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-06-13 23:30 - 2017-06-03 11:57 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-06-13 23:30 - 2017-06-03 11:56 - 06292992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-06-13 23:30 - 2017-06-03 11:55 - 03656192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-06-13 23:30 - 2017-06-03 11:55 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-06-13 23:30 - 2017-06-03 11:55 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-06-13 23:30 - 2017-06-03 11:54 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-06-13 23:30 - 2017-05-20 12:00 - 00233376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-06-13 23:30 - 2017-05-20 11:50 - 00155040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-06-13 23:30 - 2017-05-20 11:47 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-06-13 23:30 - 2017-05-20 11:46 - 00754080 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-06-13 23:30 - 2017-05-20 11:46 - 00534424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-06-13 23:30 - 2017-05-20 11:46 - 00122272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2017-06-13 23:30 - 2017-05-20 11:45 - 00480160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-06-13 23:30 - 2017-05-20 11:45 - 00259352 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2017-06-13 23:30 - 2017-05-20 11:43 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-06-13 23:30 - 2017-05-20 11:29 - 00786944 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2017-06-13 23:30 - 2017-05-20 11:27 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys
2017-06-13 23:30 - 2017-05-20 11:26 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-06-13 23:30 - 2017-05-20 11:26 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe
2017-06-13 23:30 - 2017-05-20 11:25 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-06-13 23:30 - 2017-05-20 11:25 - 00113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll
2017-06-13 23:30 - 2017-05-20 11:20 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-06-13 23:30 - 2017-05-20 11:20 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-06-13 23:30 - 2017-05-20 11:20 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-06-13 23:30 - 2017-05-20 11:17 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-06-13 23:29 - 2017-06-03 12:59 - 01427656 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-06-13 23:29 - 2017-06-03 12:59 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-06-13 23:29 - 2017-06-03 12:59 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-06-13 23:29 - 2017-06-03 12:37 - 00098208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-06-13 23:29 - 2017-06-03 12:36 - 05862304 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-06-13 23:29 - 2017-06-03 12:35 - 02259768 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-06-13 23:29 - 2017-06-03 12:33 - 00698384 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-06-13 23:29 - 2017-06-03 12:28 - 02022816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-06-13 23:29 - 2017-06-03 12:26 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-06-13 23:29 - 2017-06-03 12:23 - 20373920 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-06-13 23:29 - 2017-06-03 12:23 - 06760024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 01516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems32.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 01294752 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 01157536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 00957856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 00649632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2017-06-13 23:29 - 2017-06-03 12:21 - 00631712 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 00592800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntStreamingManager.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 00497056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 00492448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2017-06-13 23:29 - 2017-06-03 12:21 - 00288672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2017-06-13 23:29 - 2017-06-03 12:11 - 02958848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-06-13 23:29 - 2017-06-03 12:11 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2017-06-13 23:29 - 2017-06-03 12:11 - 00038912 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-06-13 23:29 - 2017-06-03 12:10 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2017-06-13 23:29 - 2017-06-03 12:07 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-06-13 23:29 - 2017-06-03 12:05 - 20506624 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-06-13 23:29 - 2017-06-03 12:05 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-06-13 23:29 - 2017-06-03 12:05 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll
2017-06-13 23:29 - 2017-06-03 11:59 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-06-13 23:29 - 2017-06-03 11:58 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-06-13 23:29 - 2017-06-03 11:57 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-06-13 23:29 - 2017-06-03 11:57 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-06-13 23:29 - 2017-06-03 11:55 - 02369536 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-06-13 23:29 - 2017-06-03 11:55 - 01844224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-06-13 23:29 - 2017-06-03 11:55 - 01585664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-06-13 23:29 - 2017-06-03 11:55 - 01560064 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-06-13 23:29 - 2017-06-03 11:55 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-06-13 23:29 - 2017-06-03 11:55 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-06-13 23:29 - 2017-06-03 11:55 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-06-13 23:29 - 2017-06-03 11:55 - 00622592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-06-13 23:29 - 2017-06-03 11:54 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-06-13 23:29 - 2017-06-03 11:54 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-06-13 23:29 - 2017-06-03 11:53 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-06-13 23:29 - 2017-06-03 11:52 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-06-13 23:29 - 2017-06-03 11:50 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe
2017-06-13 23:29 - 2017-05-20 12:13 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-06-13 23:29 - 2017-05-20 11:55 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-06-13 23:29 - 2017-05-20 11:48 - 04469832 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-06-13 23:29 - 2017-05-20 11:48 - 00297576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-06-13 23:29 - 2017-05-20 11:47 - 00755616 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-06-13 23:29 - 2017-05-20 11:47 - 00582560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-06-13 23:29 - 2017-05-20 11:46 - 05821496 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-06-13 23:29 - 2017-05-20 11:46 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-06-13 23:29 - 2017-05-20 11:46 - 00173472 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-06-13 23:29 - 2017-05-20 11:45 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-06-13 23:29 - 2017-05-20 11:44 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-06-13 23:29 - 2017-05-20 11:44 - 00296352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-06-13 23:29 - 2017-05-20 11:43 - 05802968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-06-13 23:29 - 2017-05-20 11:43 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-06-13 23:29 - 2017-05-20 11:43 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-06-13 23:29 - 2017-05-20 11:43 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-06-13 23:29 - 2017-05-20 11:43 - 01120864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-06-13 23:29 - 2017-05-20 11:43 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2017-06-13 23:29 - 2017-05-20 11:29 - 13840384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-06-13 23:29 - 2017-05-20 11:29 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-06-13 23:29 - 2017-05-20 11:29 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2017-06-13 23:29 - 2017-05-20 11:29 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll
2017-06-13 23:29 - 2017-05-20 11:27 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-06-13 23:29 - 2017-05-20 11:27 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2017-06-13 23:29 - 2017-05-20 11:26 - 00059904 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll
2017-06-13 23:29 - 2017-05-20 11:26 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-06-13 23:29 - 2017-05-20 11:24 - 00362496 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-06-13 23:29 - 2017-05-20 11:24 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
2017-06-13 23:29 - 2017-05-20 11:23 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-06-13 23:29 - 2017-05-20 11:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2017-06-13 23:29 - 2017-05-20 11:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2017-06-13 23:29 - 2017-05-20 11:22 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-06-13 23:29 - 2017-05-20 11:22 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll
2017-06-13 23:29 - 2017-05-20 11:22 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2017-06-13 23:29 - 2017-05-20 11:21 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-06-13 23:29 - 2017-05-20 11:21 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-06-13 23:29 - 2017-05-20 11:21 - 00454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2017-06-13 23:29 - 2017-05-20 11:21 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2017-06-13 23:29 - 2017-05-20 11:21 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-06-13 23:29 - 2017-05-20 11:21 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll
2017-06-13 23:29 - 2017-05-20 11:20 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-06-13 23:29 - 2017-05-20 11:19 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-06-13 23:29 - 2017-05-20 11:19 - 01208320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-06-13 23:29 - 2017-05-20 11:19 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-06-13 23:29 - 2017-05-20 11:19 - 00868352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-06-13 23:29 - 2017-05-20 11:19 - 00768000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-06-13 23:29 - 2017-05-20 11:19 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-06-13 23:29 - 2017-05-20 11:19 - 00617472 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-06-13 23:29 - 2017-05-20 11:18 - 00532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-06-13 23:29 - 2017-05-20 11:18 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-06-13 23:29 - 2017-05-20 11:17 - 01513984 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-06-13 23:29 - 2017-05-20 11:17 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-06-13 23:29 - 2017-05-20 11:17 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2017-06-13 23:29 - 2017-05-20 11:17 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-06-13 23:29 - 2017-05-20 11:16 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-06-13 23:29 - 2017-05-20 11:16 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-06-13 23:29 - 2017-05-20 11:16 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2017-06-13 23:29 - 2017-05-20 11:16 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-06-13 23:29 - 2017-05-20 11:16 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-06-13 23:29 - 2017-05-20 11:15 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-06-13 23:29 - 2017-05-20 11:15 - 01830400 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-06-13 23:29 - 2017-05-20 11:14 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-06-13 23:29 - 2017-05-20 11:14 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-06-13 23:29 - 2017-05-20 11:14 - 03097088 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-06-13 23:29 - 2017-05-20 11:14 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-06-13 23:29 - 2017-05-20 11:14 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-06-13 23:29 - 2017-05-20 11:14 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-06-13 23:29 - 2017-05-20 11:12 - 01127936 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-06-13 23:29 - 2017-05-20 11:12 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-06-13 23:29 - 2017-05-20 11:12 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2017-06-13 23:29 - 2017-05-20 11:11 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2017-06-13 23:29 - 2017-05-20 11:10 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-06-13 23:29 - 2017-05-20 11:10 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2017-06-13 23:29 - 2017-05-20 11:10 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\olepro32.dll
2017-06-13 23:29 - 2017-05-20 11:08 - 01926656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-06-13 23:28 - 2017-06-03 12:26 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll
2017-06-13 23:28 - 2017-06-03 12:23 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2017-06-13 23:28 - 2017-06-03 12:22 - 00296352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-06-13 23:28 - 2017-06-03 12:06 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe
2017-06-13 23:28 - 2017-06-03 12:04 - 00661504 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2017-06-13 23:28 - 2017-06-03 12:03 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-06-13 23:28 - 2017-06-03 11:57 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-06-13 23:28 - 2017-06-03 11:46 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe
2017-06-13 23:28 - 2017-05-20 11:50 - 00095648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2017-06-13 23:28 - 2017-05-20 11:44 - 00181664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2017-06-13 23:28 - 2017-05-20 11:25 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2017-06-13 23:28 - 2017-05-20 11:19 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2017-06-13 23:28 - 2017-05-20 11:18 - 01450496 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2017-06-13 23:28 - 2017-05-20 11:17 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-06-13 23:28 - 2017-05-20 11:11 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-06-13 23:28 - 2017-05-20 11:08 - 00524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2017-06-13 23:28 - 2017-05-20 11:08 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
2017-06-13 16:06 - 2017-06-13 16:06 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsignb95b26cbbdabd6d0
2017-06-13 16:05 - 2017-06-13 16:05 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign32e5c841e14004e9
2017-06-13 16:04 - 2017-06-13 16:04 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsignb82a00df1cc18094
2017-06-13 16:04 - 2017-06-13 16:04 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsignb49989e325fafca8
2017-06-12 20:58 - 2017-06-12 20:58 - 00220088 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\3514285E.sys
2017-06-11 23:45 - 2017-06-11 23:46 - 06822011 _____ C:\Users\hdz\Downloads\elHr6kT.psd
2017-06-11 23:09 - 2017-06-11 23:09 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsignecc01b49f37620c9
2017-06-11 23:09 - 2017-06-11 23:09 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign666cb7fd8d76bd12
2017-06-11 23:08 - 2017-06-11 23:08 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsignca2aa90fc001b739
2017-06-11 23:08 - 2017-06-11 23:08 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign98b572b3fdded430
2017-06-11 22:48 - 2017-06-11 22:48 - 00220088 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\67512E63.sys
2017-06-11 22:46 - 2017-06-11 22:46 - 00220088 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\412B2CB4.sys
2017-06-11 00:17 - 2017-06-11 00:17 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsigna44f5c779841c38b
2017-06-10 23:37 - 2017-06-10 23:37 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsignffb5da1284933d00
2017-06-10 23:36 - 2017-06-10 23:36 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign0273518d30a8a8aa
2017-06-10 23:35 - 2017-06-10 23:35 - 00000000 ____D C:\Users\hdz\AppData\Roaming\PDAppFlex
2017-06-10 23:35 - 2017-06-10 23:35 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign70c1da302d0b2e7a
2017-06-10 23:34 - 2017-06-10 23:34 - 00000000 ____D C:\Users\hdz\AppData\LocalLow\Adobe
2017-06-10 23:34 - 2017-06-10 23:34 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign8081e4cbd932f88d
2017-06-10 23:34 - 2017-06-10 23:34 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign274bbc7ba4daff82
2017-06-09 04:50 - 2017-06-09 04:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2017
2017-06-05 21:46 - 2017-06-05 21:46 - 00000000 ____D C:\Users\hdz\AppData\Local\CrashRpt
2017-06-05 21:10 - 2017-06-14 04:49 - 00000000 ____D C:\Users\hdz\AppData\Local\Discord
2017-06-01 14:19 - 2017-06-14 14:35 - 00000000 ____D C:\Users\hdz\AppData\Local\glory
2017-06-01 12:29 - 2017-06-01 12:29 - 00000000 ____D C:\Users\Public\Documents\chrome
2017-05-31 02:13 - 2017-06-08 07:00 - 00000000 ____D C:\Users\hdz\AppData\Roaming\BetterDiscord
2017-05-29 09:10 - 2017-05-29 09:10 - 00000798 _____ C:\Users\Public\Desktop\SpaceEngine 0.980.lnk
2017-05-29 09:10 - 2017-05-29 09:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpaceEngine
2017-05-29 09:04 - 2017-05-29 09:11 - 00000000 ____D C:\SpaceEngine
2017-05-29 07:18 - 2017-06-11 20:26 - 00000433 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2017-05-29 07:05 - 2017-05-29 07:05 - 00040968 _____ (Connectify) C:\WINDOWS\system32\Drivers\cfywlan2.sys
2017-05-27 17:17 - 2017-05-27 17:17 - 00000000 ____D C:\Users\hdz\AppData\Local\Bangtony
2017-05-27 14:19 - 2017-06-02 11:09 - 00000000 ____D C:\Program Files\Kjoght
2017-05-27 11:38 - 2017-05-27 11:38 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsignd96ffe0377102dfc
2017-05-27 11:38 - 2017-05-27 11:38 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsignbc44c02073dc5851
2017-05-27 11:26 - 2016-12-22 13:34 - 00000000 ____D C:\Users\hdz\Desktop\Adobe Photoshop CC 2017 Full Version
2017-05-27 11:19 - 2017-05-27 11:19 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsigne68c3bc3ac572a98
2017-05-27 11:19 - 2017-05-27 11:19 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign71ecdf7b161d640c
2017-05-27 11:19 - 2017-05-27 11:19 - 00000000 ____D C:\Users\hdz\AppData\Local\Tempzxpsign2cce897bda95e1ef
2017-05-27 10:46 - 2017-05-27 10:46 - 00001329 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017 (32 Bit).lnk
2017-05-27 09:16 - 2017-05-29 11:46 - 00000000 ___RD C:\Users\hdz\Creative Cloud Files
2017-05-27 09:16 - 2017-05-29 11:46 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-05-27 09:09 - 2017-05-27 09:09 - 00001268 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2017-05-27 09:09 - 2017-05-27 09:09 - 00001256 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2017-05-27 09:06 - 2017-05-27 09:16 - 00000000 ____D C:\Program Files\Adobe
2017-05-27 08:23 - 2017-05-27 08:23 - 03468653 _____ C:\Users\hdz\Downloads\Adobe Photoshop CC 2017.rar
2017-05-26 14:33 - 2017-05-26 14:33 - 00000000 ____D C:\Program Files\UNP
2017-05-25 21:24 - 2017-06-08 22:27 - 00004520 _____ C:\Users\hdz\Downloads\Untitled spreadsheet (1).xlsx
2017-05-25 11:54 - 2017-05-27 14:20 - 00000000 ____D C:\Users\hdz\AppData\Local\background_fault
2017-05-24 20:17 - 2017-05-24 20:17 - 00004520 _____ C:\Users\hdz\Downloads\Untitled spreadsheet.xlsx
2017-05-24 14:22 - 2017-05-27 17:18 - 00002027 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-05-24 14:22 - 2017-05-27 17:17 - 00002189 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-24 14:22 - 2017-05-24 14:22 - 00000000 ____D C:\Users\hdz\AppData\Local\Setleaf
2017-05-23 15:03 - 2017-05-29 08:35 - 00000000 ____D C:\Users\hdz\AppData\LocalLow\uTorrent
2017-05-22 13:28 - 2017-06-02 18:33 - 00000000 ____D C:\Users\hdz\AppData\Roaming\WinSAPSvc
2017-05-21 22:23 - 2017-05-21 22:23 - 00002180 _____ C:\Users\hdz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Universe Sandbox - Shortcut.lnk
2017-05-20 19:43 - 2017-05-29 20:34 - 00000000 ____D C:\WINDOWS\system32\apigidsys
2017-05-20 19:43 - 2017-05-20 19:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra Hal Assistant
2017-05-20 19:43 - 2017-05-20 19:43 - 00000000 ____D C:\WINDOWS\msagent
2017-05-20 19:29 - 2017-05-20 19:43 - 00000000 ____D C:\Program Files\Zabaware
2017-05-20 19:29 - 2017-05-20 19:29 - 00001224 _____ C:\Users\Public\Desktop\Get More Voices.lnk
2017-05-20 19:29 - 2017-05-20 19:29 - 00001179 _____ C:\Users\Public\Desktop\Zabaware Reader.lnk
2017-05-20 19:29 - 2017-05-20 19:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zabaware Reader
2017-05-19 22:47 - 2017-05-19 23:11 - 00034259 _____ C:\Users\hdz\Downloads\18372038_2011156645778792_7320203209736192000_n.mp4.crdownload
2017-05-19 09:47 - 2017-05-19 09:47 - 00000000 ___HD C:\$SysReset
2017-05-17 13:03 - 2017-05-24 14:14 - 00000000 _____ C:\WINDOWS\system32\1111
2017-05-16 15:36 - 2017-05-16 15:36 - 00036944 _____ (Anchorfree Inc.) C:\WINDOWS\system32\Drivers\taphss6.sys
2017-05-16 15:18 - 2017-05-16 15:18 - 00000000 ____D C:\Users\hdz\AppData\Local\Footjane
Edited by hdz, 14 June 2017 - 08:05 AM.