My PC has been running slower than normal for some reason over the last couple of weeks and these last 3 days it has become ever worse. I've run my antivirus as well as D/L'ing ADWCleaner and running it but not seeing any benefit.
In some cases, whatever browser I am using will stop working altogether. Facebook will run really slow, videos run real slow or appear to buffer while the audio continues to play.
Here are my FRST logs.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16.05.2018 01
Ran by Bob (administrator) on LIVING-ROOM-PC (20-05-2018 20:55:17)
Running from C:\Users\Bob\Downloads
Loaded Profiles: Bob (Available Profiles: Bob)
Platform: Windows 10 Pro Version 1803 17134.48 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGSvc.exe
(Atheros Communications, Inc.) C:\Program Files (x86)\NETGEAR\WNA1100\jswpbapi.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Alcatel-Lucent) C:\Program Files (x86)\ATT\8.5.1.16\ma\bin\MAHostService.exe
(Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\pcCMService.exe
() C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Alcatel-Lucent) C:\Program Files\Common Files\Motive\pcCMService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Novawave Inc.) C:\Program Files\Novawave\Novabench\NovabenchService.exe
(Joyent, Inc) C:\Program Files (x86)\ATT\8.5.1.16\ma\bin\node.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\x64\aswidsagenta.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.9328.1700.0_x64__8wekyb3d8bbwe\Office16\OfficeHubTaskHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.9226.21595.0_x64__8wekyb3d8bbwe\HxTsr.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17122.16211.1000_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Alcatel-Lucent) C:\Program Files\ATT\8.5.1.16\ma\bin\pcTrayApp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Alcatel-Lucent) C:\Program Files (x86)\Common Files\Motive\pcContextHookShim.exe
() C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\Antivirus\AVGUI.exe
(Facebook) C:\Users\Bob\AppData\Local\Facebook\Games\FacebookGameroom.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(The CefSharp Authors) C:\Users\Bob\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
(The Eraser Project) C:\Program Files\Eraser\Eraser.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-11-14] (NVIDIA Corporation)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files\AVG\Antivirus\AvLaunch.exe [291568 2018-05-17] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239192 2018-04-17] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [ATT_McciTrayApp] => C:\Program Files\ATT\8.5.1.16\ma\bin\pcTrayApp.exe [2943488 2015-12-11] (Alcatel-Lucent)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Eraser] => C:\Program Files\Eraser\Eraser.exe [1067024 2018-01-03] (The Eraser Project)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [588704 2018-03-28] (Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-21-110091273-928939627-1752962748-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18334016 2018-05-10] (Piriform Ltd)
HKU\S-1-5-21-110091273-928939627-1752962748-1001\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [18334016 2018-05-10] (Piriform Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNA1100 Genie.lnk [2018-03-04]
ShortcutTarget: NETGEAR WNA1100 Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe ()
Startup: C:\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2018-04-15]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Bob\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{1387eb14-e241-4983-bf86-ea62a43c1f7d}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{e00ed730-90de-4a70-a88b-77e8c02f3101}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\ssv.dll [2018-04-21] (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\jp2ssv.dll [2018-04-21] (Oracle Corporation)
Edge:
======
Edge Extension: (Honey) -> EdgeExtension_HoneyScienceCorporationHoney_cbe4c63gm1mzr => C:\Program Files\WindowsApps\HoneyScienceCorporation.Honey_10.7.2.0_neutral__cbe4c63gm1mzr [2018-05-17]
FireFox:
========
FF DefaultProfile: iewfce5i.default-1526099188072
FF ProfilePath: C:\Users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\iewfce5i.default-1526099188072 [2018-05-20]
FF Extension: (Honey) - C:\Users\Bob\AppData\Roaming\Mozilla\Firefox\Profiles\iewfce5i.default-1526099188072\Extensions\[email protected] [2018-05-14]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_29_0_0_171.dll [2018-05-09] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_171.dll [2018-05-09] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\dtplugin\npDeployJava1.dll [2018-04-21] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.171.2 -> C:\Program Files (x86)\Java\jre1.8.0_171\bin\plugin2\npjp2.dll [2018-04-21] (Oracle Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.1 -> C:\Program Files (x86)\ATT\8.5.1.16\ma\bin\npMotive.dll [2015-12-11] (AT&T)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default [2018-05-20]
CHR Extension: (Docs) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-04]
CHR Extension: (Google Drive) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-04]
CHR Extension: (YouTube) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-04]
CHR Extension: (Honey) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-05-14]
CHR Extension: (Google Docs Offline) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-03-04]
CHR Extension: (AVG SafePrice) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-03-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (AT&T Extension) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\okccnkhldjgdpjclfpdnlhlofcpginnm [2018-03-30]
CHR Extension: (Gmail) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-03-04]
CHR Extension: (Chrome Media Router) - C:\Users\Bob\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-11]
CHR HKLM\...\Chrome\Extension: [okccnkhldjgdpjclfpdnlhlofcpginnm] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [okccnkhldjgdpjclfpdnlhlofcpginnm] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AT&T Troubleshoot & Resolve; C:\Program Files (x86)\ATT\8.5.1.16\ma\bin\MAHostService.exe [321024 2015-12-11] (Alcatel-Lucent) [File not signed]
R2 AVG Antivirus; C:\Program Files\AVG\Antivirus\AVGSvc.exe [318328 2018-05-17] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files\AVG\Antivirus\x64\aswidsagenta.exe [7670672 2018-05-17] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428264 2018-04-17] (AVG Technologies CZ, s.r.o.)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-03-17] (EasyAntiCheat Ltd)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-11-14] (NVIDIA Corporation)
R2 jswpbapi; C:\Program Files (x86)\NETGEAR\WNA1100\jswpbapi.exe [241664 2012-03-26] (Atheros Communications, Inc.) [File not signed]
S3 jswpsapi; C:\Program Files (x86)\NETGEAR\WNA1100\jswpsapi.exe [1102848 2012-03-26] (Atheros Communications, Inc.) [File not signed]
R2 NovabenchService; C:\Program Files\Novawave\Novabench\NovabenchService.exe [323560 2018-03-28] (Novawave Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-11-14] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-11-14] (NVIDIA Corporation)
R2 osrss; C:\WINDOWS\system32\osrss.dll [108584 2018-01-09] (Microsoft Corporation)
R2 pcCMService; C:\Program Files (x86)\Common Files\Motive\pcCMService.exe [370176 2015-08-13] (Alcatel-Lucent) [File not signed]
R2 pcCMService64; C:\Program Files\Common Files\Motive\pcCMService.exe [462336 2015-08-13] (Alcatel-Lucent) [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S3 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [5614592 2018-01-22] (AVG Technologies CZ, s.r.o.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.14.17639.18041-0\NisSrv.exe [4632736 2018-05-01] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.14.17639.18041-0\MsMpEng.exe [104680 2018-05-01] (Microsoft Corporation)
R2 WSWNA1100; C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe [307928 2013-11-11] ()
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athur; C:\WINDOWS\System32\drivers\athuwbx.sys [2702336 2013-11-20] (Qualcomm Atheros Communications, Inc.)
R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [189032 2018-05-17] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdrivera.sys [220600 2018-05-17] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsha.sys [192536 2018-05-17] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\WINDOWS\System32\drivers\avgbloga.sys [336848 2018-05-17] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniva.sys [50776 2018-05-17] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\WINDOWS\System32\drivers\avgHwid.sys [39352 2018-05-17] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [151504 2018-05-17] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [103744 2018-05-17] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [78352 2018-05-17] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [1020112 2018-05-17] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [452904 2018-05-17] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [198368 2018-05-17] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [373944 2018-05-17] (AVG Technologies CZ, s.r.o.)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MREMP50a64; C:\Program Files\Common Files\Motive\MREMP50a64.sys [43008 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50a64; C:\Program Files\Common Files\Motive\MRESP50a64.sys [40960 2010-02-02] (Printing Communications Assoc., Inc. (PCAUSA))
R3 NovabenchDriver; C:\Program Files\Novawave\Novabench\NovabenchDriverWin10.sys [28216 2018-03-28] ()
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-11-14] (NVIDIA Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-11] (Realtek )
S3 smbdirect; C:\WINDOWS\System32\DRIVERS\smbdirect.sys [152064 2018-04-12] (Microsoft Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2018-01-22] (AVG Netherlands B.V.)
U5 vwifimp; C:\Windows\System32\Drivers\vwifimp.sys [44544 2018-04-11] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46072 2018-05-01] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [313888 2018-05-01] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61472 2018-05-01] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-05-20 20:55 - 2018-05-20 20:55 - 000016771 _____ C:\Users\Bob\Downloads\FRST.txt
2018-05-20 20:28 - 2018-05-20 20:28 - 002413056 _____ (Farbar) C:\Users\Bob\Downloads\FRST64.exe
2018-05-20 20:04 - 2018-05-20 20:04 - 000001828 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Eraser.lnk
2018-05-20 20:04 - 2018-05-20 20:04 - 000001816 _____ C:\Users\Public\Desktop\Eraser.lnk
2018-05-20 20:04 - 2018-05-20 20:04 - 000000000 ____D C:\Program Files\Eraser
2018-05-20 19:57 - 2018-05-20 20:02 - 009101000 _____ (The Eraser Project) C:\Users\Bob\Downloads\Eraser 6.2.0.2982.exe
2018-05-20 07:06 - 2018-05-20 03:25 - 000000000 ____D C:\Windows.old
2018-05-20 03:29 - 2018-05-20 03:29 - 000000000 ___HD C:\OneDriveTemp
2018-05-20 03:28 - 2018-05-20 03:28 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-05-20 03:26 - 2018-05-20 03:26 - 000000000 ____D C:\Users\Bob\AppData\Local\PackageStaging
2018-05-20 03:25 - 2018-05-20 03:25 - 000000020 ___SH C:\Users\Bob\ntuser.ini
2018-05-20 03:24 - 2018-05-20 19:49 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-05-20 03:24 - 2018-05-20 18:58 - 000004158 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A29677FF-757A-4AC8-8014-4228864E097C}
2018-05-20 03:24 - 2018-05-20 18:56 - 000004266 _____ C:\WINDOWS\System32\Tasks\Antivirus Emergency Update
2018-05-20 03:24 - 2018-05-20 03:28 - 000003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2018-05-20 03:24 - 2018-05-20 03:25 - 000003748 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-05-20 03:24 - 2018-05-20 03:25 - 000003446 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2018-05-20 03:24 - 2018-05-20 03:25 - 000003044 _____ C:\WINDOWS\System32\Tasks\update-S-1-5-21-110091273-928939627-1752962748-1001
2018-05-20 03:24 - 2018-05-20 03:25 - 000002852 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-110091273-928939627-1752962748-1001
2018-05-20 03:24 - 2018-05-20 03:25 - 000002796 _____ C:\WINDOWS\System32\Tasks\update-sys
2018-05-20 03:24 - 2018-05-20 03:25 - 000002216 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-05-20 03:24 - 2018-05-20 03:24 - 000003346 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-05-20 03:24 - 2018-05-20 03:24 - 000003122 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-05-20 03:24 - 2018-05-20 03:24 - 000003094 _____ C:\WINDOWS\System32\Tasks\Java Platform SE Auto Updater
2018-05-20 03:24 - 2018-05-20 03:24 - 000002988 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-05-20 03:24 - 2018-05-20 03:24 - 000002038 _____ C:\WINDOWS\System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance
2018-05-20 03:24 - 2018-05-20 03:24 - 000000000 ____D C:\WINDOWS\System32\Tasks\AVG
2018-05-20 03:23 - 2018-05-20 03:24 - 000007623 _____ C:\WINDOWS\diagwrn.xml
2018-05-20 03:23 - 2018-05-20 03:24 - 000007623 _____ C:\WINDOWS\diagerr.xml
2018-05-20 03:21 - 2018-05-20 19:56 - 000838560 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-05-20 03:12 - 2018-05-20 03:12 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-05-20 03:10 - 2018-05-20 19:48 - 000000000 ____D C:\Users\Bob
2018-05-20 03:10 - 2018-05-20 03:10 - 000000000 ____D C:\ProgramData\USOShared
2018-05-20 03:10 - 2018-04-11 19:34 - 000001105 _____ C:\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-05-20 03:10 - 2018-04-11 19:33 - 002752000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-05-20 03:07 - 2018-05-20 19:13 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-05-20 03:07 - 2018-05-20 03:13 - 000233856 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-05-20 00:10 - 2018-05-17 10:02 - 001020112 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000452904 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000373944 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000336848 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbloga.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000220600 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdrivera.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000198368 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000192536 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsha.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000189032 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000151504 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000103744 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000078352 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000050776 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniva.sys
2018-05-20 00:10 - 2018-05-17 10:02 - 000039352 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgHwid.sys
2018-05-20 00:08 - 2018-05-17 10:02 - 000377584 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2018-05-20 00:07 - 2018-05-20 07:06 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-05-19 23:55 - 2018-05-20 00:06 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-05-19 23:44 - 2018-05-19 23:44 - 013570560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-05-19 23:44 - 2018-05-19 23:44 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 025848832 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 023862272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 022707712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 022002688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 021389360 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 020383720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 019399168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 012712960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 011903488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 009159064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-05-19 23:43 - 2018-05-19 23:43 - 008623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 007583232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 007519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 006661632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 006569952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 006044104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 005782528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 004867072 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 004372992 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 003732800 _____ C:\WINDOWS\system32\Windows.Mirage.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 003712000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 003440640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 003389952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 003015168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002961408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002900992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002841312 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002753040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002700800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002486976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002422168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-05-19 23:43 - 2018-05-19 23:43 - 002366976 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002242208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 002170368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001817088 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001664512 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001636352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001634800 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001456616 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-05-19 23:43 - 2018-05-19 23:43 - 001454016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001426328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-05-19 23:43 - 2018-05-19 23:43 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001191168 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 001034624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-05-19 23:43 - 2018-05-19 23:43 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-05-19 23:43 - 2018-05-19 23:43 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000860160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000814592 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000786168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000775680 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2018-05-19 23:43 - 2018-05-19 23:43 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2018-05-19 23:43 - 2018-05-19 23:43 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000559968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-05-19 23:43 - 2018-05-19 23:43 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 007436624 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 005951488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 004929024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 004070400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 003655168 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-05-19 23:42 - 2018-05-19 23:42 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 003283400 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 003086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 002902528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 002897408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-05-19 23:42 - 2018-05-19 23:42 - 002835864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-05-19 23:42 - 2018-05-19 23:42 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-05-19 23:42 - 2018-05-19 23:42 - 001953280 _____ C:\WINDOWS\system32\rdpnano.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 001565592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 001534976 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 001174424 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-05-19 23:42 - 2018-05-19 23:42 - 001160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 001063320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-05-19 23:42 - 2018-05-19 23:42 - 001012120 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-05-19 23:42 - 2018-05-19 23:42 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000885848 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000826776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2018-05-19 23:42 - 2018-05-19 23:42 - 000788216 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000776880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000749976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000733992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000709816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-05-19 23:42 - 2018-05-19 23:42 - 000705944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-05-19 23:42 - 2018-05-19 23:42 - 000665320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000652184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs4.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000606448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000604568 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-05-19 23:42 - 2018-05-19 23:42 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs3.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000567136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2018-05-19 23:42 - 2018-05-19 23:42 - 000474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs2.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000473496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs1.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000434584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2018-05-19 23:42 - 2018-05-19 23:42 - 000399768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000382872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2018-05-19 23:42 - 2018-05-19 23:42 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.th.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000272288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000269216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win81.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000170904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-05-19 23:42 - 2018-05-19 23:42 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win8rtm.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000134552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2018-05-19 23:42 - 2018-05-19 23:42 - 000001312 _____ C:\WINDOWS\system32\tcbres.wim
2018-05-19 23:24 - 2018-05-19 23:24 - 004492288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2018-05-19 23:24 - 2018-05-19 23:24 - 003398144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2018-05-19 23:24 - 2018-05-19 23:24 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2018-05-19 23:24 - 2018-05-19 23:24 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2018-05-19 23:24 - 2018-05-19 23:24 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2018-05-19 23:24 - 2018-05-19 23:24 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2018-05-19 23:24 - 2018-05-19 23:24 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2018-05-19 23:24 - 2018-05-19 23:24 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2018-05-19 23:23 - 2018-05-19 23:23 - 000000000 ____D C:\Program Files\Reference Assemblies
2018-05-19 23:23 - 2018-05-19 23:23 - 000000000 ____D C:\Program Files\MSBuild
2018-05-19 23:23 - 2018-05-19 23:23 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2018-05-19 23:23 - 2018-05-19 23:23 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-05-19 23:21 - 2018-05-19 23:21 - 001166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2018-05-19 23:21 - 2018-05-19 23:21 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2018-05-19 23:21 - 2018-05-19 23:21 - 000124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2018-05-19 23:21 - 2018-05-19 23:21 - 000103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2018-05-19 23:21 - 2018-05-19 23:21 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2018-05-19 23:21 - 2018-05-19 23:21 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2018-05-19 23:03 - 2018-05-19 23:03 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-05-19 22:50 - 2018-05-19 22:50 - 000000047 _____ C:\Users\Bob\Desktop\Card Rates.txt
2018-05-19 20:42 - 2018-05-20 18:58 - 000000000 ___DC C:\WINDOWS\Panther
2018-05-19 13:10 - 2018-05-19 13:35 - 000000433 _____ C:\Users\Bob\Desktop\My concerts.txt
2018-05-18 22:33 - 2018-05-18 22:33 - 000034349 _____ C:\Users\Bob\Desktop\Facebook-Like-Button-big.jpeg
2018-05-17 10:02 - 2018-05-17 10:02 - 000001878 _____ C:\Users\Public\Desktop\AVG AntiVirus FREE.lnk
2018-05-17 09:56 - 2018-05-17 09:56 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-05-14 20:05 - 2018-05-14 20:05 - 000000090 _____ C:\Users\Bob\Desktop\PWtxt.txt
2018-05-13 17:16 - 2018-05-13 17:18 - 000000000 ____D C:\Users\Bob\Desktop\New folder
2018-05-12 00:24 - 2018-05-12 00:24 - 000021720 _____ C:\Users\Bob\Desktop\bookmarks-2018-05-12.json
2018-05-05 15:33 - 2018-05-05 15:46 - 1515048215 _____ C:\Users\Bob\Downloads\facebook-BBQbyBob.zip
2018-05-03 21:41 - 2018-05-05 19:40 - 000000000 ____D C:\Users\Bob\AppData\Local\Jagex
2018-05-03 21:41 - 2018-05-05 19:40 - 000000000 ____D C:\ProgramData\Jagex
2018-05-03 21:41 - 2018-05-03 21:41 - 000000000 ____D C:\Users\Bob\AppData\Roaming\NVIDIA
2018-05-03 21:40 - 2018-05-03 21:40 - 004940656 _____ (Jagex Ltd ) C:\Users\Bob\Downloads\RuneScape-Setup.exe
2018-05-03 21:40 - 2018-05-03 21:40 - 000000177 _____ C:\Users\Public\Desktop\RuneScape Launcher.url
2018-05-03 21:40 - 2018-05-03 21:40 - 000000000 ____D C:\Program Files\Jagex
2018-04-30 18:02 - 2018-04-30 18:02 - 003934419 _____ C:\Users\Bob\Downloads\TWDrewards_Carl_Wallpaper.zip
2018-04-25 00:51 - 2018-04-25 00:51 - 000002553 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Excel Viewer.lnk
2018-04-25 00:51 - 2018-04-25 00:51 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-04-25 00:48 - 2018-04-25 00:48 - 077738888 _____ (Microsoft Corporation) C:\Users\Bob\Downloads\ExcelViewer.exe
2018-04-25 00:48 - 2018-04-25 00:48 - 000000000 ____D C:\Program Files (x86)\MSECache
2018-04-25 00:45 - 2018-04-25 00:46 - 000050688 _____ C:\Users\Bob\Downloads\BBQ Catering Workbook.xls
2018-04-23 17:44 - 2018-04-23 17:44 - 000021324 _____ C:\Users\Bob\Desktop\bookmarks-2018-04-23.json
2018-04-21 14:36 - 2018-05-10 20:09 - 000000000 ____D C:\Users\Bob\Desktop\stylopics
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-05-20 20:55 - 2018-04-04 00:46 - 000000000 ____D C:\FRST
2018-05-20 20:24 - 2018-04-03 22:04 - 000000000 ____D C:\Users\Bob\Downloads\Antivirus Programs
2018-05-20 20:24 - 2018-03-04 01:58 - 000000000 ____D C:\Users\Bob\AppData\LocalLow\Mozilla
2018-05-20 20:23 - 2018-04-11 19:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-05-20 19:56 - 2018-04-11 19:36 - 000000000 ____D C:\WINDOWS\INF
2018-05-20 19:54 - 2018-03-04 00:53 - 000000000 ___RD C:\Users\Bob\OneDrive
2018-05-20 19:50 - 2018-03-28 00:00 - 000000000 ____D C:\Program Files (x86)\ATT
2018-05-20 19:48 - 2018-04-11 17:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-05-20 19:32 - 2018-04-03 22:05 - 000000000 ____D C:\AdwCleaner
2018-05-20 19:29 - 2018-03-04 21:53 - 000000000 ____D C:\Users\Bob\AppData\Local\PlaceholderTileLogoFolder
2018-05-20 19:26 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-05-20 18:57 - 2018-04-11 19:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-05-20 07:06 - 2018-04-11 19:41 - 000000000 ____D C:\WINDOWS\Setup
2018-05-20 07:06 - 2018-04-11 19:38 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-05-20 07:06 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-05-20 07:06 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-05-20 07:06 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\spool
2018-05-20 07:06 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-05-20 07:06 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-05-20 07:06 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\Help
2018-05-20 07:06 - 2018-04-04 01:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-05-20 07:06 - 2018-03-28 00:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATT
2018-05-20 07:06 - 2018-03-04 21:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2018-05-20 07:06 - 2018-03-04 01:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-05-20 07:06 - 2018-03-04 00:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WNA1100 Genie
2018-05-20 07:06 - 2018-03-03 22:29 - 000000000 ____D C:\Program Files\UNP
2018-05-20 07:06 - 2017-09-29 09:46 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-05-20 03:45 - 2018-04-11 19:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-05-20 03:43 - 2018-03-04 00:50 - 000000000 ____D C:\Users\Bob\AppData\Local\Packages
2018-05-20 03:42 - 2018-04-11 19:38 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-05-20 03:26 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\Registration
2018-05-20 03:26 - 2018-03-04 01:37 - 000000000 ___RD C:\Users\Bob\3D Objects
2018-05-20 03:26 - 2016-02-13 09:22 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-05-20 03:25 - 2018-04-11 17:04 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-05-20 03:24 - 2018-04-11 19:38 - 000000000 ____D C:\Program Files\Windows Defender
2018-05-20 03:19 - 2018-04-11 19:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-05-20 03:18 - 2018-04-04 01:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-05-20 03:18 - 2018-03-04 01:28 - 000022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2018-05-20 03:16 - 2018-03-04 01:48 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-05-20 03:12 - 2018-04-15 17:15 - 000000000 ____D C:\Users\Bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
2018-05-20 03:10 - 2018-04-11 19:38 - 000000000 ____D C:\ProgramData\USOPrivate
2018-05-20 03:09 - 2018-03-04 00:55 - 000000000 ____D C:\temp
2018-05-20 03:09 - 2018-03-03 22:22 - 000000000 ____D C:\ProgramData\NVIDIA
2018-05-20 03:08 - 2018-03-03 22:21 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-05-20 00:18 - 2018-04-11 19:38 - 000000000 __RHD C:\Users\Public\Libraries
2018-05-20 00:08 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\appcompat
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-05-19 23:48 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-05-19 23:48 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-05-19 23:48 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-05-19 23:47 - 2018-04-12 05:37 - 000000000 ____D C:\WINDOWS\Containers
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-05-19 23:47 - 2018-04-12 05:19 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\ta-in
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\si-lk
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\setup
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\am-et
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\Provisioning
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-05-19 23:47 - 2018-04-11 19:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\SysWOW64\en-GB
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\et-EE
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\es-MX
2018-05-19 23:24 - 2018-04-11 19:38 - 000000000 ____D C:\WINDOWS\system32\en-GB
2018-05-19 20:32 - 2018-03-04 01:58 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-05-19 20:32 - 2018-03-04 01:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-05-18 14:16 - 2018-04-12 12:27 - 000000000 ____D C:\Users\Bob\AppData\Local\CrashDumps
2018-05-18 12:58 - 2018-03-04 01:58 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-05-15 22:24 - 2018-03-13 23:16 - 000000000 ____D C:\Program Files (x86)\AVG
2018-05-15 22:24 - 2018-03-04 02:10 - 000000000 ____D C:\ProgramData\AVG
2018-05-15 17:49 - 2018-03-04 21:20 - 000000416 _____ C:\WINDOWS\Tasks\update-sys.job
2018-05-15 17:49 - 2018-03-04 21:20 - 000000416 _____ C:\WINDOWS\Tasks\update-S-1-5-21-110091273-928939627-1752962748-1001.job
2018-05-12 00:26 - 2018-03-23 01:03 - 000000000 ____D C:\Users\Bob\Desktop\Old Firefox Data
2018-05-09 18:59 - 2018-03-04 02:21 - 000000042 _____ C:\Users\Bob\jagex_cl_oldschool_LIVE.dat
2018-05-09 18:58 - 2018-03-04 02:20 - 000000000 ____D C:\Users\Bob\OSBuddy
2018-05-08 19:48 - 2018-03-03 22:49 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-05-08 19:46 - 2018-03-03 22:49 - 141696960 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-05-08 19:46 - 2018-03-03 22:49 - 141696960 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-05-07 10:53 - 2018-03-04 21:52 - 000000000 ____D C:\Users\Bob\AppData\Local\ElevatedDiagnostics
2018-05-01 17:22 - 2018-04-11 19:41 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-05-01 17:22 - 2018-04-11 19:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-05-01 00:29 - 2018-03-28 15:34 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-04-21 19:57 - 2018-04-04 01:02 - 000000000 ____D C:\Program Files (x86)\Java
2018-04-21 19:55 - 2018-04-04 01:02 - 000098760 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
==================== Files in the root of some directories =======
2018-03-23 21:24 - 2018-03-23 21:24 - 000000017 _____ () C:\Users\Bob\AppData\Local\resmon.resmoncfg
2018-03-04 21:20 - 2018-03-04 21:20 - 000000003 _____ () C:\Users\Bob\AppData\Local\updater.log
2018-03-04 21:20 - 2018-03-04 21:20 - 000000425 _____ () C:\Users\Bob\AppData\Local\UserProducts.xml
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-05-20 03:07
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16.05.2018 01
Ran by Bob (20-05-2018 20:56:04)
Running from C:\Users\Bob\Downloads
Windows 10 Pro Version 1803 17134.48 (X64) (2018-05-20 07:25:41)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-110091273-928939627-1752962748-500 - Administrator - Disabled)
Bob (S-1-5-21-110091273-928939627-1752962748-1001 - Administrator - Enabled) => C:\Users\Bob
DefaultAccount (S-1-5-21-110091273-928939627-1752962748-503 - Limited - Disabled)
Guest (S-1-5-21-110091273-928939627-1752962748-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-110091273-928939627-1752962748-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {C50510DE-367A-330C-FD5C-556ACFB11243}
AS: AVG Antivirus (Enabled - Up to date) {7E64F13A-1040-3C82-C7EC-6E18B43658FE}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 29 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 29.0.0.171 - Adobe Systems Incorporated)
AT&T Troubleshoot & Resolve (HKLM-x32\...\ATT-AT&T Troubleshoot & Resolve) (Version: 8.5.1.16 - AT&T)
AVG AntiVirus FREE (HKLM-x32\...\AVG Antivirus) (Version: 18.4.3056 - AVG Technologies)
AVG PC TuneUp (HKLM-x32\...\{9C775BB6-1453-45EB-8C78-A5CC5199113D}) (Version: 16.77.3 - AVG Technologies) Hidden
AVG PC TuneUp (HKLM-x32\...\AVG PC TuneUp) (Version: 16.77.3.23060 - AVG Technologies)
CCleaner (HKLM\...\CCleaner) (Version: 5.42 - Piriform)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Eraser 6.2.0.2982 (HKLM\...\{DFCF78CC-3DAD-4C1E-8BC6-94DC5B73461E}) (Version: 6.2.2982 - The Eraser Project)
Facebook Gameroom 1.21.6663.39782 (HKLM-x32\...\{68176DF0-3139-406A-955D-E90916FB9EE8}) (Version: 1.21.6663.39782 - Facebook)
FMW 1 (HKLM\...\{DFA0CE4A-C162-40C1-A977-12E60098EB72}) (Version: 1.227.11 - AVG Technologies) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.181 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Lightshot-5.4.0.35 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.35 - Skillbrains)
Microsoft Office Excel Viewer (HKLM-x32\...\{95120000-003F-0409-0000-0000000FF1CE}) (Version: 12.0.6219.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-110091273-928939627-1752962748-1001\...\OneDriveSetup.exe) (Version: 18.065.0329.0002 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Firefox 60.0.1 (x64 en-US) (HKLM\...\Mozilla Firefox 60.0.1 (x64 en-US)) (Version: 60.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 58.0.2 - Mozilla)
NETGEAR WNA1100 N150 Wireless USB Adapter (HKLM-x32\...\{A2AE9709-283B-4B48-AA34-729C070A62FB}) (Version: 2.2.0.1 - NETGEAR)
Novabench (HKLM\...\{2FAC7FB5-8FA6-46F2-826D-B2757EFC2E83}) (Version: 4.0.4 - Novawave Inc.)
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.11.4.125 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.4.125 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
RuneScape Launcher 2.2.4 (HKLM\...\RuneScape Launcher_is1) (Version: 2.2.4 - Jagex Ltd)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 2.11.4.125 - NVIDIA Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{E345A108-D9E8-456B-9550-435132D5C9CE}) (Version: 2.13.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{567756E0-361F-4E88-AF74-8B0E4628E5BC}) (Version: 1.12.0.0 - Microsoft Corporation) Hidden
Windows Setup Remediations (x64) (KB4023057) (HKLM\...\{5534e02f-0f5d-40dd-ba92-bea38d22384d}.sdb) (Version: - )
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShA64.dll [2018-05-17] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [AVG Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [2018-01-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (The Eraser Project)
ContextMenuHandlers2: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (The Eraser Project)
ContextMenuHandlers4: [AVG Disk Space Explorer Shell Extension] -> {4838CD50-7E5D-4811-9B17-C47A85539F28} => C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x64.dll [2018-01-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers4: [AVG Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [2018-01-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers4: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (The Eraser Project)
ContextMenuHandlers5: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (The Eraser Project)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2016-11-14] (NVIDIA Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVG\Antivirus\ashShA64.dll [2018-05-17] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [Eraser] -> {BC9B776A-90D7-4476-A791-79D835F30650} => C:\Program Files\Eraser\Eraser.Shell.dll [2018-01-03] (The Eraser Project)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1568C8CB-4699-47F2-85FF-6775FC0F51CC} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {406087F9-818F-4AD3-BA4C-05255D7FD5B9} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-04] (Google Inc.)
Task: {505BC152-7781-4A1D-80A4-8C7179B99EB9} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe [2018-01-22] (AVG Technologies CZ, s.r.o.)
Task: {5967FD50-EF61-4F46-B2C2-7D48D25D8271} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {7B6D3B6A-1B17-4517-AFDF-792758A6D30C} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-03-28] (Oracle Corporation)
Task: {9E82F1DC-7939-4B6A-A861-64CB00471DE6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-04] (Google Inc.)
Task: {9F419D81-4A68-4243-A5C9-11EC31AF7FAD} - System32\Tasks\update-S-1-5-21-110091273-928939627-1752962748-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2017-04-12] (TODO: <Company name>)
Task: {9FF858A6-AEA2-4707-8DFE-8C83093407FF} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-05-10] (Piriform Ltd)
Task: {B44C3BAB-0831-4417-A443-9CE3AD55398E} - System32\Tasks\Microsoft\Windows\Setup\Notifier => C:\WINDOWS\system32\Notifier.exe
Task: {B8BCA3F2-8ECC-4AA6-BE4A-FBB6A4B30868} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_171_Plugin.exe [2018-05-09] (Adobe Systems Incorporated)
Task: {D3C35613-421B-4634-A028-CBC689B4CD30} - System32\Tasks\Antivirus Emergency Update => C:\Program Files\AVG\Antivirus\AvEmUpdate.exe [2018-05-17] (AVG Technologies CZ, s.r.o.)
Task: {DDE06B86-C55F-4D0F-A746-DBADF70C8E9C} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2017-04-12] (TODO: <Company name>)
Task: {E5B7F4E2-ADD9-44DB-A7F6-83E89BF94B1C} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-05-09] (Adobe Systems Incorporated)
Task: {F43BCF6A-6D01-4871-B79D-7D98AD832E22} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-05-10] (Piriform Ltd)
Task: {FC7AAA12-AD95-4C43-A622-A0688944F3D0} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2018-05-16] (AVG Technologies CZ, s.r.o.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\update-S-1-5-21-110091273-928939627-1752962748-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2018-03-03 22:22 - 2016-11-14 07:15 - 000135224 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2018-03-04 00:56 - 2013-11-11 19:10 - 000307928 _____ () C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvc.exe
2018-04-11 19:34 - 2018-04-11 19:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-11 19:34 - 2018-04-11 19:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 19:34 - 2018-04-11 19:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-04-11 19:35 - 2018-04-12 05:20 - 002184704 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-04-24 15:23 - 2018-04-24 15:24 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-04-24 15:23 - 2018-04-24 15:24 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-04-24 15:23 - 2018-04-24 15:24 - 022320128 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-04-24 15:23 - 2018-04-24 15:24 - 002603008 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\skypert.dll
2018-04-24 15:23 - 2018-04-24 15:24 - 000657408 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2018-04-16 17:11 - 2018-04-16 17:13 - 001922232 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.9328.1700.0_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll
2018-03-04 02:11 - 2018-03-04 02:12 - 027139072 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17122.16211.1000_x64__8wekyb3d8bbwe\Video.UI.exe
2018-03-04 02:11 - 2018-03-04 02:12 - 000306176 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17122.16211.1000_x64__8wekyb3d8bbwe\SharedUI.dll
2018-03-04 02:11 - 2018-03-04 02:12 - 006687744 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17122.16211.1000_x64__8wekyb3d8bbwe\EntCommon.dll
2018-03-03 23:11 - 2018-03-03 23:14 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17122.16211.1000_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-03-04 02:11 - 2018-03-04 02:12 - 009283072 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17122.16211.1000_x64__8wekyb3d8bbwe\EntPlat.dll
2018-03-04 00:56 - 2014-01-02 17:13 - 008266456 _____ () C:\Program Files (x86)\NETGEAR\WNA1100\WNA1100.exe
2018-03-04 00:56 - 2013-10-15 13:29 - 000372736 _____ () C:\Program Files (x86)\NETGEAR\WNA1100\WifiLib.dll
2015-12-07 19:44 - 2015-12-07 19:44 - 000270336 _____ () C:\Program Files (x86)\ATT\8.5.1.16\ma\node_modules\motive-osbridge\build\Release\MotiveOSBridgeNodeModule.node
2015-12-07 19:44 - 2015-12-07 19:44 - 000244736 _____ () C:\Program Files (x86)\ATT\8.5.1.16\ma\node_modules\motive-activex-wrapper\build\Release\NodeActiveXWrapper.node
2013-04-24 08:55 - 2013-04-24 08:55 - 001581056 _____ () C:\Program Files (x86)\ATT\8.5.1.16\ma\node_modules\libxmljs\build\Release\xmljs.node
2015-12-07 19:44 - 2015-12-07 19:44 - 000237056 _____ () C:\Program Files (x86)\ATT\8.5.1.16\ma\node_modules\motive-xmpps\build\Release\MotiveXMPPSNode.node
2018-04-04 01:14 - 2016-11-14 08:30 - 000018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2018-03-13 23:16 - 2018-03-13 23:14 - 048920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2018-03-04 00:56 - 2013-11-01 21:31 - 000278528 _____ () C:\Program Files (x86)\NETGEAR\WNA1100\WifiSvcLib.dll
2018-03-04 02:13 - 2018-03-04 02:13 - 067127976 _____ () C:\Program Files\AVG\Antivirus\libcef.dll
2018-05-17 10:02 - 2018-05-17 10:02 - 000481008 _____ () C:\Program Files\AVG\Antivirus\streamback.dll
2018-03-27 10:25 - 2018-03-27 10:25 - 001184256 _____ () C:\Users\Bob\AppData\Local\Facebook\Games\CefSharp.Core.dll
2018-03-27 10:25 - 2018-03-27 10:25 - 071641088 _____ () C:\Users\Bob\AppData\Local\Facebook\Games\libcef.dll
2018-03-27 10:25 - 2018-03-27 10:25 - 000774656 _____ () C:\Users\Bob\AppData\Local\Facebook\Games\CefSharp.BrowserSubprocess.Core.dll
2018-03-27 10:25 - 2018-03-27 10:25 - 003149824 _____ () C:\Users\Bob\AppData\Local\Facebook\Games\libglesv2.dll
2018-03-27 10:25 - 2018-03-27 10:25 - 000078848 _____ () C:\Users\Bob\AppData\Local\Facebook\Games\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Public\AppData:CSM [474]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-10-30 03:24 - 2015-10-30 03:21 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-110091273-928939627-1752962748-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Bob\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\24131584_1891126297602629_8616179405180199500_n.jpg
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{7BD599DA-A477-4361-8587-CC6D2E1C20E8}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{ABF490BB-0AB3-45E0-8B8E-B3FF9DAD76B9}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{F9AACAF2-7FBB-4B6E-A868-632BF543302D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Restore Points =========================
20-05-2018 18:56:37 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (05/20/2018 08:50:02 PM) (Source: ESENT) (EventID: 467) (User: )
Description: svchost (2916,D,23) SRUJet: Database C:\WINDOWS\system32\SRU\SRUDB.dat: Index UserIdTimeStamp of table {5C8CF1C7-7257-4F13-B223-970EF5939312} is corrupted (0).
Error: (05/20/2018 06:55:47 PM) (Source: ESENT) (EventID: 467) (User: )
Description: svchost (2868,D,23) SRUJet: Database C:\WINDOWS\system32\SRU\SRUDB.dat: Index UserIdTimeStamp of table {5C8CF1C7-7257-4F13-B223-970EF5939312} is corrupted (0).
Error: (05/20/2018 06:55:47 PM) (Source: ESENT) (EventID: 467) (User: )
Description: svchost (2868,D,23) SRUJet: Database C:\WINDOWS\system32\SRU\SRUDB.dat: Index UserIdTimeStamp of table {5C8CF1C7-7257-4F13-B223-970EF5939312} is corrupted (0).
Error: (05/20/2018 06:55:45 PM) (Source: ESENT) (EventID: 467) (User: )
Description: svchost (2868,D,23) SRUJet: Database C:\WINDOWS\system32\SRU\SRUDB.dat: Index UserIdTimeStamp of table {5C8CF1C7-7257-4F13-B223-970EF5939312} is corrupted (0).
Error: (05/20/2018 03:23:13 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider wsp_sr attempted to register query "select * from WSP_ReplicationGroupModificationEvent" whose target class "WSP_ReplicationGroupModificationEvent" in //./root/Microsoft/Windows/Storage/Providers_v2 namespace does not exist. The query will be ignored.
Error: (05/20/2018 03:23:13 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider wsp_sr attempted to register query "select * from WSP_ReplicationGroupDepartureEvent" whose target class "WSP_ReplicationGroupDepartureEvent" in //./root/Microsoft/Windows/Storage/Providers_v2 namespace does not exist. The query will be ignored.
Error: (05/20/2018 03:23:13 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider wsp_sr attempted to register query "select * from WSP_ReplicationGroupArrivalEvent" whose target class "WSP_ReplicationGroupArrivalEvent" in //./root/Microsoft/Windows/Storage/Providers_v2 namespace does not exist. The query will be ignored.
Error: (05/20/2018 03:23:13 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider attempted to register query "select * from WSP_ReplicationGroupModificationEvent" whose target class "WSP_ReplicationGroupModificationEvent" in //./root/Microsoft/Windows/Storage/Providers_v2 namespace does not exist. The query will be ignored.
System errors:
=============
Error: (05/20/2018 07:53:12 PM) (Source: DCOM) (EventID: 10001) (User: LIVING-ROOM-PC)
Description: Unable to start a DCOM Server: Microsoft.Windows.Cortana_1.10.7.17134_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppXd4tad4d57t4wtdbnnmb8v2xtzym8c1n8.mca as Unavailable/Unavailable. The error:
"298"
Happened while starting this command:
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
Error: (05/20/2018 07:35:35 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The AVG PC TuneUp Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 250 milliseconds: Restart the service.
Error: (05/20/2018 07:35:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Novabench Service service terminated unexpectedly. It has done this 1 time(s).
Error: (05/20/2018 07:35:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Network Service service terminated unexpectedly. It has done this 1 time(s).
Error: (05/20/2018 07:35:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The pcCMService64 service terminated unexpectedly. It has done this 1 time(s).
Error: (05/20/2018 07:35:35 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The WSWNA1100 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
Error: (05/20/2018 07:35:35 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The AT&T Troubleshoot & Resolve service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
Error: (05/20/2018 07:35:35 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The pcCMService service terminated unexpectedly. It has done this 1 time(s).
==================== Memory info ===========================
Processor: Intel® Core2 Duo CPU E8400 @ 3.00GHz
Percentage of memory in use: 66%
Total physical RAM: 4094.49 MB
Available physical RAM: 1378.46 MB
Total Virtual: 5502.49 MB
Available Virtual: 2269.51 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:930.95 GB) (Free:879.63 GB) NTFS
\\?\Volume{9dabe905-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{9dabe905-0000-0000-0000-70c3e8000000}\ () (Fixed) (Total:0.46 GB) (Free:0.08 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 9DABE905)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=468 MB) - (Type=27)
==================== End of Addition.txt ============================