Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

AIO repair found lots of errors (previous virus infection apparently t


  • Please log in to reply

#1
Channeal

Channeal

    Member

  • Member
  • PipPipPip
  • 889 posts

Hello there,
 
I have been getting help in the tech forums and recently did a clean install of Windows 10 on the old Sonny Vaio which was given to me by my daughter.
 (see http://www.geekstogo...esolved/page-12)
 
Almost immediately after downloading the new OS,  I clicked on something by mistake when downloading something else - and some strange program downloaded. I am afraid I cannot remember what it was called. I immediately did a virus check as well as a malware check with Malwarebytes.
 
I was so annoyed with myself for letting this thing download immediately after loading the OS that I somehow just obliterated all memory of this from my mind (in my defence, life has been pretty stressful recently).However, I suddenly started getting problems with Microsoft Edge refusing to open and Phillpower2 got me to run the All In One repair program which found loads of errors to correct, including one which mentioned it being caused by an infection. It was only then that I remembered what had happened! :(
 
I just looked in the Malwarebytes logs and was very surprised to see how much was quarantined. (I still have no memory whatsoever of seeing those entries at the time). I will add the Farbar logs below and copy the Malwarebytes log afterwards. (I just did a Malwarebytes scan and it didn't come up with anything else btw.)
 
Please can you help me check that all is okay now?
 
Chris.
(feeling very stupid!)
 
EDIT looking through the logs below myself, there still seem to be some things not right and I am now leaning towards starting over and doing another clean install. Please could somebody just have a quick look at the logs (without preparing fixes) and let me know your thoughts on this idea? I just feel that my nice new OS has been spoiled by this and I would probably be happier starting again!
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 16-10-2016
Ran by chann (administrator) on NEAL2-SONYVAIO (24-10-2016 15:04:21)
Running from C:\Users\chann\Desktop
Loaded Profiles: chann (Available Profiles: defaultuser0 & chann)
Platform: Microsoft Windows 10 Home Version 1607 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX86\officeclicktorun.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Trend Micro Inc.) C:\Program Files\Trend Micro\DRScanner\DRScanner.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Spotify Ltd) C:\Users\chann\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x86__kzf8qxf38zg5c\SkypeHost.exe
(Tweaking.com) C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Insecure.Org) C:\Program Files\Trend Micro\DRScanner\nmap\nmap.exe

==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3531952 2016-01-07] (Synaptics Incorporated)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [483840 2016-07-16] (Microsoft Corporation)
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\...\Run: [Chromium] => c:\users\chann\appdata\local\chromium\application\chrome.exe [1068544 2016-03-18] (The Chromium Authors)
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\...\Run: [Spotify Web Helper] => C:\Users\chann\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1529456 2016-09-30] (Spotify Ltd)
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6889176 2016-09-28] (Piriform Ltd)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
GroupPolicy: Restriction ? <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100
Tcpip\..\Interfaces\{270722f4-8789-46a3-be70-3d8d385571eb}: [DhcpNameServer] 194.168.4.100 194.168.8.100
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?bcutc=sp-006
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.google.com/?bcutc=sp-006
SearchScopes: HKLM -> DefaultScope {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKLM -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2764644833-1114247620-3834938357-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_16_39&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dgb%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutCtBtBtAyE0D0EtByD0Bzzzy0FtC0DyEtN0D0Tzu0StCyBtAtBtN1L2XzutAtFtByEtFtCyBtFyDyEtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StD0B0AyByCyEzztAtGtD0EtCyEtG0CyDyC0AtGtA0DzztDtGyDyCyEyDyEtBtB0D0CyByD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0CtA0Fzy0DyCtDtG0CyB0A0EtGyEtCtD0DtGzy0CyB0AtGyBtBtDtByD0E0AyDtBtD0Dzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDtC%26cr%3D1879745563%26a%3Dwbf_ir_16_39%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2764644833-1114247620-3834938357-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_16_39&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dgb%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutCtBtBtAyE0D0EtByD0Bzzzy0FtC0DyEtN0D0Tzu0StCyBtAtBtN1L2XzutAtFtByEtFtCyBtFyDyEtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StD0B0AyByCyEzztAtGtD0EtCyEtG0CyDyC0AtGtA0DzztDtGyDyCyEyDyEtBtB0D0CyByD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0CtA0Fzy0DyCtDtG0CyB0A0EtGyEtCtD0DtGzy0CyB0AtGyBtBtDtByD0E0AyDtBtD0Dzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDtC%26cr%3D1879745563%26a%3Dwbf_ir_16_39%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2764644833-1114247620-3834938357-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?bcutc=sp-006&q={searchTerms}
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-10-23] (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-10-23] (Google Inc.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-10-03] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2764644833-1114247620-3834938357-1001 -> hxxp://uk.yahoo.com/
FireFox:
========
FF DefaultProfile: porhbv4g.default
FF ProfilePath: C:\Users\chann\AppData\Roaming\Mozilla\Firefox\Profiles\porhbv4g.default [2016-10-24]
FF NewTab: Mozilla\Firefox\Profiles\porhbv4g.default -> about:newtab
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\porhbv4g.default -> Google
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\porhbv4g.default -> hxxps://www.google.com/search?bcutc=sp-006
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\porhbv4g.default -> Google
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\porhbv4g.default -> Google
FF Homepage: Mozilla\Firefox\Profiles\porhbv4g.default -> uk.yahoo.com
FF Keyword.URL: Mozilla\Firefox\Profiles\porhbv4g.default -> hxxps://www.google.com/search?bcutc=sp-006
FF SearchPlugin: C:\Users\chann\AppData\Roaming\Mozilla\Firefox\Profiles\porhbv4g.default\searchplugins\google-avast.xml [2016-09-29]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2016-10-03] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-10-04] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-10-04] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://uk.yahoo.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\chann\AppData\Local\Google\Chrome\User Data\Default [2016-10-23]
CHR Extension: (Google Docs) - C:\Users\chann\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\chann\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-04]
CHR Extension: (Chrome Media Router) - C:\Users\chann\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-04]
Opera:
=======
OPR StartupUrls: "hxxp://uk.yahoo.com/"
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [2039536 2016-10-03] (Microsoft Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [217264 2016-01-07] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [271496 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [84928 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\System32\drivers\athwn.sys [3228672 2016-07-16] (Qualcomm Atheros Communications, Inc.)
R2 giveio; C:\Windows\system32\giveio.sys [5248 1996-04-03] () [File not signed]
S0 megasas2i; C:\Windows\System32\drivers\MegaSas2i.sys [56672 2016-10-05] (Avago Technologies)
R1 MpKsle7adbc9f; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4BC9CE93-5905-483F-B4B7-8F9E61D17004}\MpKsle7adbc9f.sys [39168 2016-10-23] (Microsoft Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [62976 2016-07-16] ()
R3 npf; C:\Windows\System32\drivers\npf.sys [36600 2014-08-19] (Riverbed Technology, Inc.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [35504 2016-01-07] (Synaptics Incorporated)
R2 speedfan; C:\Windows\system32\speedfan.sys [24184 2012-12-29] (Almico Software)
R1 tmcomm; C:\Windows\system32\DRIVERS\tmcomm.sys [323808 2016-08-22] (Trend Micro Inc.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [37912 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [244576 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [100192 2016-07-16] (Microsoft Corporation)
R3 yukonw8; C:\Windows\System32\drivers\yk63x86.sys [242688 2016-07-16] (Marvell)
U0 aswVmm; no ImagePath
S3 cpuz140; \??\C:\Users\chann\AppData\Local\Temp\cpuz140\cpuz140_x32.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-10-24 15:04 - 2016-10-24 15:05 - 00012102 _____ C:\Users\chann\Desktop\FRST.txt
2016-10-24 15:01 - 2016-10-24 15:01 - 00000000 ____D C:\Program Files\WinPcap
2016-10-24 14:59 - 2016-10-24 15:04 - 00000000 ____D C:\FRST
2016-10-24 14:58 - 2016-10-24 14:59 - 01756672 _____ (Farbar) C:\Users\chann\Desktop\FRST.exe
2016-10-24 13:06 - 2016-10-24 13:06 - 00000000 ____D C:\Program Files\Mozilla Firefox
2016-10-24 10:36 - 2016-10-24 10:36 - 00000000 ____D C:\Program Files\Trend Micro
2016-10-24 10:24 - 2016-10-24 10:24 - 00865841 _____ C:\Users\chann\AppData\Local\census.cache
2016-10-24 10:22 - 2016-10-24 10:22 - 01115164 _____ C:\Users\chann\AppData\Local\ars.cache
2016-10-24 10:11 - 2016-10-24 10:11 - 00000010 _____ C:\Users\chann\AppData\Local\sponge.last.runtime.cache
2016-10-24 10:02 - 2016-10-24 10:02 - 00000000 ____D C:\Windows\Trend Micro
2016-10-24 10:02 - 2016-10-24 10:02 - 00000000 ____D C:\ProgramData\Trend Micro
2016-10-24 09:59 - 2016-10-24 09:59 - 02105760 _____ (Trend Micro Inc.) C:\Users\chann\Downloads\HousecallLauncher.exe
2016-10-24 09:59 - 2016-10-24 09:59 - 00000036 _____ C:\Users\chann\AppData\Local\housecall.guid.cache
2016-10-24 09:59 - 2016-08-22 20:20 - 00323808 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmcomm.sys
2016-10-23 22:13 - 2016-10-23 22:13 - 00002385 _____ C:\Users\chann\Desktop\_Windows_Repair_Log - Shortcut.lnk
2016-10-23 19:25 - 2016-10-23 19:25 - 00000207 _____ C:\Windows\tweaking.com-regbackup-NEAL2-SONYVAIO-Windows-10-Home-(32-bit).dat
2016-10-23 19:25 - 2016-10-23 19:25 - 00000000 ____D C:\RegBackup
2016-10-23 19:14 - 2016-10-23 19:14 - 00002194 _____ C:\Users\chann\Desktop\Tweaking.com - Windows Repair.lnk
2016-10-23 19:14 - 2016-10-23 19:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2016-10-23 19:13 - 2016-10-23 19:14 - 00181887 _____ C:\Windows\Tweaking.com - Windows Repair Setup Log.txt
2016-10-23 19:13 - 2016-10-23 19:13 - 29306344 _____ (Tweaking.com) C:\Users\chann\Downloads\tweaking.com_windows_repair_aio_setup.exe
2016-10-23 19:13 - 2016-10-23 19:13 - 00000000 ____D C:\Program Files\Tweaking.com
2016-10-23 17:38 - 2016-10-23 17:38 - 00001038 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-10-23 17:38 - 2016-10-23 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-10-23 17:38 - 2016-10-23 17:38 - 00000000 ____D C:\ProgramData\Google
2016-10-23 17:38 - 2016-10-23 17:38 - 00000000 ____D C:\Program Files\CCleaner
2016-10-22 11:09 - 2016-10-22 11:09 - 00875012 _____ C:\Users\chann\Downloads\add_gpedit_msc_by_jwils876-d3kh6vm.zip
2016-10-22 11:09 - 2016-10-22 11:09 - 00707354 _____ C:\Windows\unins000.exe
2016-10-22 11:09 - 2016-10-22 11:09 - 00001537 _____ C:\Windows\unins000.dat
2016-10-22 11:09 - 2016-10-22 11:09 - 00000000 ____D C:\Windows\system32\GPBAK
2016-10-22 11:09 - 2008-04-14 02:11 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\appmgr.dll
2016-10-22 11:09 - 2001-08-23 13:00 - 00034871 _____ C:\Windows\system32\gpedit.msc
2016-10-22 09:59 - 2016-10-23 19:56 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2016-10-22 09:58 - 2016-10-23 22:21 - 00000000 ____D C:\Windows\pss
2016-10-21 17:13 - 2016-10-21 17:13 - 00001129 _____ C:\Users\chann\Desktop\Public - Shortcut.lnk
2016-10-21 16:30 - 2016-10-21 16:30 - 00000000 ____D C:\Users\Public\Documents\SVP
2016-10-21 15:43 - 2016-10-21 15:44 - 00214172 _____ C:\Windows\Minidump\102116-25484-01.dmp
2016-10-21 15:43 - 2016-10-21 15:43 - 190446207 _____ C:\Windows\MEMORY.DMP
2016-10-21 15:43 - 2016-10-21 15:43 - 00000000 ____D C:\Windows\Minidump
2016-10-21 13:46 - 2016-10-24 09:56 - 00040960 ___SH C:\Users\chann\Desktop\Thumbs.db
2016-10-21 10:40 - 2016-10-21 10:40 - 00000000 ____D C:\Users\chann\AppData\Local\ElevatedDiagnostics
2016-10-21 10:36 - 2016-10-21 10:36 - 00000000 ____D C:\Users\chann\AppData\Local\__SHARED
2016-10-14 15:48 - 2016-10-14 15:48 - 01191360 _____ ( ) C:\Users\chann\Downloads\hwmonitor_1.30.exe
2016-10-11 21:24 - 2016-10-05 11:03 - 06015840 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-10-11 21:24 - 2016-10-05 10:59 - 00949600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2016-10-11 21:24 - 2016-10-05 10:54 - 01097568 _____ (Microsoft Corporation) C:\Windows\system32\wpx.dll
2016-10-11 21:24 - 2016-10-05 10:51 - 01430720 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2016-10-11 21:24 - 2016-10-05 10:50 - 02256592 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-10-11 21:24 - 2016-10-05 10:49 - 01980768 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2016-10-11 21:24 - 2016-10-05 10:46 - 00056672 _____ (Avago Technologies) C:\Windows\system32\Drivers\MegaSas2i.sys
2016-10-11 21:24 - 2016-10-05 10:41 - 00545944 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2016-10-11 21:24 - 2016-10-05 10:28 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2016-10-11 21:24 - 2016-10-05 10:28 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.dll
2016-10-11 21:24 - 2016-10-05 10:28 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.HostName.dll
2016-10-11 21:24 - 2016-10-05 10:27 - 00229888 _____ C:\Windows\system32\wc_storage.dll
2016-10-11 21:24 - 2016-10-05 10:27 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-11 21:24 - 2016-10-05 10:26 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2016-10-11 21:24 - 2016-10-05 10:26 - 00182784 _____ (Microsoft Corporation) C:\Windows\system32\mfsensorgroup.dll
2016-10-11 21:24 - 2016-10-05 10:26 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.Ngc.dll
2016-10-11 21:24 - 2016-10-05 10:25 - 00822784 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2016-10-11 21:24 - 2016-10-05 10:25 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\dsreg.dll
2016-10-11 21:24 - 2016-10-05 10:25 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll
2016-10-11 21:24 - 2016-10-05 10:25 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2016-10-11 21:24 - 2016-10-05 10:25 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\AuthBroker.dll
2016-10-11 21:24 - 2016-10-05 10:23 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2016-10-11 21:24 - 2016-10-05 10:23 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs3D.dll
2016-10-11 21:24 - 2016-10-05 10:22 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2016-10-11 21:24 - 2016-10-05 10:21 - 03689984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-10-11 21:24 - 2016-10-05 10:21 - 00498176 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2016-10-11 21:24 - 2016-10-05 10:20 - 00661504 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2016-10-11 21:24 - 2016-10-05 10:20 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2016-10-11 21:24 - 2016-10-05 10:18 - 01283584 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2016-10-11 21:24 - 2016-10-05 10:16 - 19418624 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-10-11 21:24 - 2016-10-05 10:16 - 00508416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-10-11 21:24 - 2016-10-05 10:14 - 19416576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-10-11 21:24 - 2016-10-05 10:14 - 01456640 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2016-10-11 21:24 - 2016-10-05 10:14 - 01255936 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2016-10-11 21:24 - 2016-10-05 10:11 - 06108672 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2016-10-11 21:24 - 2016-10-05 10:11 - 06043136 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-10-11 21:24 - 2016-10-05 10:11 - 01135616 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2016-10-11 21:24 - 2016-10-05 10:11 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\FrameServer.dll
2016-10-11 21:24 - 2016-10-05 10:10 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\ngcsvc.dll
2016-10-11 21:24 - 2016-10-05 10:09 - 07467520 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2016-10-11 21:24 - 2016-10-05 10:09 - 00674304 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2016-10-11 21:24 - 2016-10-05 10:09 - 00608256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2016-10-11 21:24 - 2016-10-05 10:08 - 02356736 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-10-11 21:24 - 2016-10-05 10:08 - 01524224 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-10-11 21:24 - 2016-10-05 10:08 - 00598528 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.dll
2016-10-11 21:24 - 2016-10-05 10:07 - 03667456 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-10-11 21:24 - 2016-10-05 10:07 - 02682880 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2016-10-11 21:24 - 2016-10-05 10:07 - 02646016 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2016-10-11 21:24 - 2016-10-05 10:07 - 01123328 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-10-11 21:24 - 2016-10-05 10:07 - 00589312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
2016-10-11 21:24 - 2016-10-05 10:07 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
2016-10-11 21:24 - 2016-10-05 10:06 - 02999296 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2016-10-11 21:24 - 2016-10-05 10:06 - 02254336 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-10-11 21:24 - 2016-10-05 10:06 - 02005504 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-10-11 21:24 - 2016-10-05 10:06 - 01594368 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-10-11 21:24 - 2016-10-05 10:06 - 01013248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Http.dll
2016-10-11 21:24 - 2016-10-05 10:06 - 00711680 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2016-10-11 21:24 - 2016-10-05 10:05 - 03105792 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2016-10-11 21:24 - 2016-10-05 10:05 - 00751104 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-11 21:24 - 2016-09-23 04:59 - 00446124 _____ C:\Windows\system32\ApnDatabase.xml
2016-10-11 21:24 - 2016-09-07 06:18 - 00290264 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2016-10-11 21:23 - 2016-10-05 11:10 - 00231776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2016-10-11 21:23 - 2016-10-05 11:05 - 00892008 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-10-11 21:23 - 2016-10-05 11:05 - 00784576 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2016-10-11 21:23 - 2016-10-05 11:05 - 00099680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tm.sys
2016-10-11 21:23 - 2016-10-05 11:03 - 01724584 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-10-11 21:23 - 2016-10-05 11:03 - 01072280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-10-11 21:23 - 2016-10-05 11:03 - 00946272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2016-10-11 21:23 - 2016-10-05 10:53 - 00154976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2016-10-11 21:23 - 2016-10-05 10:50 - 00116576 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
2016-10-11 21:23 - 2016-10-05 10:48 - 01022304 _____ (Microsoft Corporation) C:\Windows\system32\AppxPackaging.dll
2016-10-11 21:23 - 2016-10-05 10:46 - 03892352 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2016-10-11 21:23 - 2016-10-05 10:46 - 01360456 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2016-10-11 21:23 - 2016-10-05 10:46 - 00980824 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2016-10-11 21:23 - 2016-10-05 10:45 - 00198496 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2016-10-11 21:23 - 2016-10-05 10:40 - 01968480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2016-10-11 21:23 - 2016-10-05 10:31 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\ConfigureExpandedStorage.dll
2016-10-11 21:23 - 2016-10-05 10:27 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-10-11 21:23 - 2016-10-05 10:26 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2016-10-11 21:23 - 2016-10-05 10:26 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\credprovs.dll
2016-10-11 21:23 - 2016-10-05 10:25 - 00299520 _____ (Microsoft Corporation) C:\Windows\system32\UserDataAccountApis.dll
2016-10-11 21:23 - 2016-10-05 10:24 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.AllJoyn.dll
2016-10-11 21:23 - 2016-10-05 10:24 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-10-11 21:23 - 2016-10-05 10:23 - 00431616 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
2016-10-11 21:23 - 2016-10-05 10:23 - 00426496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Wallet.dll
2016-10-11 21:23 - 2016-10-05 10:23 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2016-10-11 21:23 - 2016-10-05 10:23 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2016-10-11 21:23 - 2016-10-05 10:22 - 00790528 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2016-10-11 21:23 - 2016-10-05 10:21 - 00567808 _____ (Microsoft Corporation) C:\Windows\system32\ChatApis.dll
2016-10-11 21:23 - 2016-10-05 10:21 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2016-10-11 21:23 - 2016-10-05 10:18 - 04612608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2016-10-11 21:23 - 2016-10-05 10:18 - 00858112 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll
2016-10-11 21:23 - 2016-10-05 10:17 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2016-10-11 21:23 - 2016-10-05 10:15 - 01375232 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2016-10-11 21:23 - 2016-10-05 10:15 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\dialclient.dll
2016-10-11 21:23 - 2016-10-05 10:13 - 12345856 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-10-11 21:23 - 2016-10-05 10:13 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\offreg.dll
2016-10-11 21:23 - 2016-10-05 10:11 - 12174848 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-10-11 21:23 - 2016-10-05 10:11 - 03776000 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2016-10-11 21:23 - 2016-10-05 10:11 - 01938944 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-10-11 21:23 - 2016-10-05 10:11 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-10-11 21:23 - 2016-10-05 10:10 - 06474752 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe
2016-10-11 21:23 - 2016-10-05 10:09 - 03369984 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2016-10-11 21:23 - 2016-10-05 10:09 - 01700864 _____ (Microsoft Corporation) C:\Windows\system32\smartscreen.exe
2016-10-11 21:23 - 2016-10-05 10:09 - 00884224 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-10-11 21:23 - 2016-10-05 10:09 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentApis.dll
2016-10-11 21:23 - 2016-10-05 10:09 - 00691712 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-10-11 21:23 - 2016-10-05 10:08 - 01485312 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-10-11 21:23 - 2016-10-05 10:08 - 00873472 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2016-10-11 21:23 - 2016-10-05 10:07 - 01232384 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2016-10-11 21:23 - 2016-10-05 10:06 - 01880576 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-10-11 21:23 - 2016-10-05 10:06 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll
2016-10-10 18:26 - 2016-10-10 18:26 - 00000000 ____D C:\Users\chann\Documents\Custom Office Templates
2016-10-10 17:24 - 2016-10-10 17:24 - 00000000 __RHD C:\MSOCache
2016-10-07 14:00 - 2016-10-22 13:16 - 00000000 ____D C:\Users\chann\Documents\St George's Website
2016-10-07 13:52 - 2016-10-07 13:52 - 00097386 _____ C:\Users\chann\Downloads\Bulletin (5).pdf
2016-10-07 13:52 - 2016-10-07 13:52 - 00097386 _____ C:\Users\chann\Downloads\Bulletin (4).pdf
2016-10-07 13:47 - 2016-10-07 13:47 - 00097983 _____ C:\Users\chann\Downloads\Bulletin (3).pdf
2016-10-07 13:40 - 2016-10-07 13:40 - 00377015 _____ C:\Users\chann\Downloads\Bulletin (2).pdf
2016-10-07 13:35 - 2016-10-07 13:35 - 00258096 _____ C:\Users\chann\Downloads\Bulletin (1).pdf
2016-10-07 12:47 - 2016-10-07 12:48 - 00350394 _____ C:\Users\chann\Downloads\Bulletin.pdf
2016-10-06 19:14 - 2016-10-06 19:14 - 03815886 _____ C:\Users\chann\Desktop\bindays.pdf
2016-10-04 11:30 - 2016-10-04 11:30 - 00000000 ____D C:\Users\chann\AppData\LocalLow\Adobe
2016-10-04 11:02 - 2016-10-23 18:21 - 00000000 ____D C:\Users\chann\AppData\Local\Google
2016-10-04 10:51 - 2016-10-04 11:02 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-10-04 10:51 - 2016-10-04 11:02 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-10-04 10:50 - 2016-10-23 22:24 - 00000926 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-10-04 10:50 - 2016-10-23 22:24 - 00000922 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-10-04 10:50 - 2016-10-23 17:38 - 00000000 ____D C:\Program Files\Google
2016-10-04 10:50 - 2016-10-11 21:15 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-10-04 10:50 - 2016-10-04 10:51 - 00000000 ____D C:\Program Files\GUMA87.tmp
2016-10-04 10:50 - 2016-10-04 10:50 - 00002094 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-10-04 10:49 - 2016-10-04 11:31 - 00000000 ____D C:\ProgramData\Adobe
2016-10-04 10:49 - 2016-10-04 10:49 - 00000000 ____D C:\Program Files\Common Files\Adobe
2016-10-04 10:49 - 2016-10-04 10:49 - 00000000 ____D C:\Program Files\Adobe
2016-10-04 10:48 - 2016-10-04 11:30 - 00000000 ____D C:\Users\chann\AppData\Local\Adobe
2016-10-03 21:47 - 2016-07-15 18:45 - 08229888 _____ (Microsoft Corporation) C:\Windows\system32\prm0008.dll
2016-10-03 18:12 - 2016-10-03 18:13 - 00002460 _____ C:\Users\chann\Desktop\Word 2013.lnk
2016-10-03 16:38 - 2016-10-03 16:38 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-10-03 16:33 - 2016-10-03 16:33 - 00000000 ____D C:\Users\chann\AppData\Local\Microsoft Help
2016-10-03 16:30 - 2016-10-03 16:30 - 00000000 ____D C:\Program Files\Microsoft Office
2016-10-03 16:29 - 2016-10-20 10:21 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-10-03 16:29 - 2016-10-03 16:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-10-03 16:29 - 2016-10-03 16:29 - 01129200 _____ (Microsoft Corporation) C:\Users\chann\Downloads\Setup.X86.en-US_HomeStudentRetail_0f4ad016-e96c-49ee-9d0b-99cf58453a37_TX_DB_.exe
2016-10-02 17:24 - 2003-06-18 17:31 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\mdimon.dll
2016-10-02 17:02 - 2016-10-02 17:02 - 00000000 _____ C:\Users\chann\AppData\Roaming\wklnhst.dat
2016-10-02 16:59 - 2016-10-02 17:24 - 00000376 _____ C:\Windows\ODBC.INI
2016-10-02 13:59 - 2016-10-02 13:59 - 00000000 ____D C:\Users\chann\AppData\LocalLow\Temp
2016-10-02 13:57 - 2016-10-21 12:37 - 00000000 ____D C:\Users\chann\Documents\SVP
2016-10-02 13:56 - 2016-10-02 13:56 - 00000000 ____D C:\Users\chann\Documents\A Meze Of Greek Verbs
2016-10-02 13:54 - 2016-10-02 13:54 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-10-01 17:07 - 2016-10-01 17:22 - 00001318 _____ C:\Users\chann\Desktop\mspaint.lnk
2016-10-01 14:40 - 2016-10-21 10:56 - 00001078 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2016-10-01 14:40 - 2016-10-21 10:56 - 00000000 ____D C:\Program Files\Opera
2016-10-01 14:40 - 2016-10-01 14:40 - 00001166 _____ C:\Users\Public\Desktop\Opera.lnk
2016-10-01 14:40 - 2016-10-01 14:40 - 00000000 ____D C:\Users\chann\AppData\Roaming\Opera Software
2016-10-01 14:40 - 2016-10-01 14:40 - 00000000 ____D C:\Users\chann\AppData\Local\Opera Software
2016-10-01 14:39 - 2016-10-01 14:39 - 01137328 _____ (Opera Software) C:\Users\chann\Downloads\OperaSetup.exe
2016-09-30 20:46 - 2016-10-02 14:10 - 00000000 ____D C:\Users\chann\AppData\Local\Spotify
2016-09-30 20:46 - 2016-10-02 13:03 - 00000000 ____D C:\Users\chann\AppData\Roaming\Spotify
2016-09-30 20:46 - 2016-09-30 20:46 - 00356056 _____ (Spotify Ltd) C:\Users\chann\Downloads\SpotifySetup.exe
2016-09-30 20:46 - 2016-09-30 20:46 - 00001850 _____ C:\Users\chann\Desktop\Spotify.lnk
2016-09-30 20:46 - 2016-09-30 20:46 - 00001836 _____ C:\Users\chann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2016-09-30 19:16 - 2016-09-30 19:16 - 12754672 _____ (Microsoft Corporation) C:\Users\chann\Downloads\MP10Setup (1).exe
2016-09-30 19:14 - 2016-09-30 19:14 - 12754672 _____ (Microsoft Corporation) C:\Users\chann\Downloads\MP10Setup.exe
2016-09-30 13:03 - 2016-09-15 19:14 - 00484584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-09-30 13:03 - 2016-09-15 18:37 - 00496872 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2016-09-30 13:03 - 2016-09-15 18:35 - 00455040 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll
2016-09-30 13:03 - 2016-09-15 18:35 - 00356704 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2016-09-30 13:03 - 2016-09-15 18:35 - 00356704 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2016-09-30 13:03 - 2016-09-15 18:31 - 00583648 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2016-09-30 13:03 - 2016-09-15 18:27 - 00868704 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2016-09-30 13:03 - 2016-09-15 18:23 - 01503032 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2016-09-30 13:03 - 2016-09-15 18:14 - 01413664 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2016-09-30 13:03 - 2016-09-15 18:13 - 01264912 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-09-30 13:03 - 2016-09-15 18:13 - 00113504 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2016-09-30 13:03 - 2016-09-15 17:58 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\provops.dll
2016-09-30 13:03 - 2016-09-15 17:57 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.LowLevel.dll
2016-09-30 13:03 - 2016-09-15 17:57 - 00272896 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2016-09-30 13:03 - 2016-09-15 17:57 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll
2016-09-30 13:03 - 2016-09-15 17:57 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\BthRadioMedia.dll
2016-09-30 13:03 - 2016-09-15 17:56 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2016-09-30 13:03 - 2016-09-15 17:55 - 00332288 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2016-09-30 13:03 - 2016-09-15 17:55 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2016-09-30 13:03 - 2016-09-15 17:54 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\icsvc.dll
2016-09-30 13:03 - 2016-09-15 17:54 - 00204800 _____ (Microsoft Corporation) C:\Windows\system32\ConsoleLogon.dll
2016-09-30 13:03 - 2016-09-15 17:54 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-09-30 13:03 - 2016-09-15 17:52 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\cryptngc.dll
2016-09-30 13:03 - 2016-09-15 17:49 - 00901120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
2016-09-30 13:03 - 2016-09-15 17:49 - 00653312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
2016-09-30 13:03 - 2016-09-15 17:49 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2016-09-30 13:03 - 2016-09-15 17:48 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-09-30 13:03 - 2016-09-15 17:46 - 00795648 _____ (Microsoft Corporation) C:\Windows\system32\MiracastReceiver.dll
2016-09-30 13:03 - 2016-09-15 17:44 - 00786432 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-09-30 13:03 - 2016-09-15 17:36 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2016-09-30 13:03 - 2016-09-15 17:36 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\FontProvider.dll
2016-09-30 13:02 - 2016-09-15 18:42 - 01144600 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2016-09-30 13:02 - 2016-09-15 18:42 - 00448864 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2016-09-30 13:02 - 2016-09-15 18:40 - 00965472 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2016-09-30 13:02 - 2016-09-15 18:38 - 04970224 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2016-09-30 13:02 - 2016-09-15 18:37 - 00402352 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2016-09-30 13:02 - 2016-09-15 18:37 - 00320152 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe
2016-09-30 13:02 - 2016-09-15 18:35 - 01583112 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-09-30 13:02 - 2016-09-15 18:35 - 00470368 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-09-30 13:02 - 2016-09-15 18:34 - 00106336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2016-09-30 13:02 - 2016-09-15 18:33 - 00083120 _____ (Microsoft Corporation) C:\Windows\system32\devenum.dll
2016-09-30 13:02 - 2016-09-15 18:32 - 02048496 _____ C:\Windows\system32\CoreUIComponents.dll
2016-09-30 13:02 - 2016-09-15 18:32 - 00279416 _____ (Microsoft Corporation) C:\Windows\system32\bdeunlock.exe
2016-09-30 13:02 - 2016-09-15 18:28 - 01015648 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-09-30 13:02 - 2016-09-15 18:26 - 00581672 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2016-09-30 13:02 - 2016-09-15 18:25 - 00340320 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-09-30 13:02 - 2016-09-15 18:25 - 00262960 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
2016-09-30 13:02 - 2016-09-15 18:23 - 01897824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2016-09-30 13:02 - 2016-09-15 18:23 - 00550240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2016-09-30 13:02 - 2016-09-15 18:23 - 00342368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2016-09-30 13:02 - 2016-09-15 18:23 - 00170448 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-09-30 13:02 - 2016-09-15 18:22 - 05722320 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2016-09-30 13:02 - 2016-09-15 18:22 - 00975744 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2016-09-30 13:02 - 2016-09-15 18:22 - 00860512 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2016-09-30 13:02 - 2016-09-15 18:22 - 00433832 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll
2016-09-30 13:02 - 2016-09-15 18:22 - 00111968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storahci.sys
2016-09-30 13:02 - 2016-09-15 18:21 - 00557920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2016-09-30 13:02 - 2016-09-15 18:21 - 00458592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2016-09-30 13:02 - 2016-09-15 18:21 - 00357216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2016-09-30 13:02 - 2016-09-15 18:21 - 00272720 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2016-09-30 13:02 - 2016-09-15 18:21 - 00261984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2016-09-30 13:02 - 2016-09-15 18:21 - 00186720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-09-30 13:02 - 2016-09-15 18:21 - 00175968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys
2016-09-30 13:02 - 2016-09-15 18:20 - 00846560 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2016-09-30 13:02 - 2016-09-15 18:20 - 00095072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wcifs.sys
2016-09-30 13:02 - 2016-09-15 18:19 - 00361104 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2016-09-30 13:02 - 2016-09-15 18:19 - 00080224 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2016-09-30 13:02 - 2016-09-15 18:18 - 06654616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2016-09-30 13:02 - 2016-09-15 18:18 - 01201872 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2016-09-30 13:02 - 2016-09-15 18:18 - 01123368 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-09-30 13:02 - 2016-09-15 18:18 - 00955528 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2016-09-30 13:02 - 2016-09-15 18:18 - 00856872 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2016-09-30 13:02 - 2016-09-15 18:17 - 20965248 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-09-30 13:02 - 2016-09-15 18:17 - 01384704 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2016-09-30 13:02 - 2016-09-15 18:17 - 00834128 _____ (Microsoft Corporation) C:\Windows\system32\EditionUpgradeManagerObj.dll
2016-09-30 13:02 - 2016-09-15 18:17 - 00702416 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2016-09-30 13:02 - 2016-09-15 18:16 - 00093984 _____ (Microsoft Corporation) C:\Windows\system32\phoneactivate.exe
2016-09-30 13:02 - 2016-09-15 18:13 - 01276608 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-09-30 13:02 - 2016-09-15 18:13 - 00484544 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-09-30 13:02 - 2016-09-15 18:12 - 00781664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2016-09-30 13:02 - 2016-09-15 18:12 - 00046784 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-09-30 13:02 - 2016-09-15 18:08 - 05683712 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2016-09-30 13:02 - 2016-09-15 18:06 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\ffbroker.dll
2016-09-30 13:02 - 2016-09-15 18:03 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2016-09-30 13:02 - 2016-09-15 18:03 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
2016-09-30 13:02 - 2016-09-15 18:02 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\mfksproxy.dll
2016-09-30 13:02 - 2016-09-15 18:02 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll
2016-09-30 13:02 - 2016-09-15 18:01 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Radios.dll
2016-09-30 13:02 - 2016-09-15 18:01 - 00114688 _____ (Microsoft Corporation) C:\Windows\splwow64.exe
2016-09-30 13:02 - 2016-09-15 18:01 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\findnetprinters.dll
2016-09-30 13:02 - 2016-09-15 18:00 - 00554496 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2016-09-30 13:02 - 2016-09-15 18:00 - 00518656 _____ (Microsoft Corporation) C:\Windows\system32\ngccredprov.dll
2016-09-30 13:02 - 2016-09-15 18:00 - 00399360 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2016-09-30 13:02 - 2016-09-15 18:00 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\BcastDVRHelper.dll
2016-09-30 13:02 - 2016-09-15 18:00 - 00138240 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2016-09-30 13:02 - 2016-09-15 18:00 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\NfcRadioMedia.dll
2016-09-30 13:02 - 2016-09-15 18:00 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys
2016-09-30 13:02 - 2016-09-15 17:59 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2016-09-30 13:02 - 2016-09-15 17:59 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\credprovslegacy.dll
2016-09-30 13:02 - 2016-09-15 17:59 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\WinRtTracing.dll
2016-09-30 13:02 - 2016-09-15 17:58 - 00491008 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.exe
2016-09-30 13:02 - 2016-09-15 17:58 - 00329728 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2016-09-30 13:02 - 2016-09-15 17:58 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\cdpusersvc.dll
2016-09-30 13:02 - 2016-09-15 17:58 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\credprovhost.dll
2016-09-30 13:02 - 2016-09-15 17:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFi.dll
2016-09-30 13:02 - 2016-09-15 17:58 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2016-09-30 13:02 - 2016-09-15 17:58 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2016-09-30 13:02 - 2016-09-15 17:58 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2016-09-30 13:02 - 2016-09-15 17:58 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.UserDeviceAssociation.dll
2016-09-30 13:02 - 2016-09-15 17:57 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Input.dll
2016-09-30 13:02 - 2016-09-15 17:57 - 00315904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll
2016-09-30 13:02 - 2016-09-15 17:57 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll
2016-09-30 13:02 - 2016-09-15 17:57 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2016-09-30 13:02 - 2016-09-15 17:57 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2016-09-30 13:02 - 2016-09-15 17:57 - 00184832 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Flights.dll
2016-09-30 13:02 - 2016-09-15 17:57 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2016-09-30 13:02 - 2016-09-15 17:57 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ClipboardServer.dll
2016-09-30 13:02 - 2016-09-15 17:57 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 01300480 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00823808 _____ (Microsoft Corporation) C:\Windows\system32\nettrace.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Import.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManager.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00554496 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00257536 _____ (Microsoft Corporation) C:\Windows\system32\DataExchange.dll
2016-09-30 13:02 - 2016-09-15 17:56 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\RMapi.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00562176 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00386048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFiDirect.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00378368 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnrGidsHandler.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00332800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00322048 _____ (Microsoft Corporation) C:\Windows\system32\WpAXHolder.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\cdpsvc.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\usbmon.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2016-09-30 13:02 - 2016-09-15 17:55 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.CredDialogController.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\biwinrt.dll
2016-09-30 13:02 - 2016-09-15 17:55 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\setupugc.exe
2016-09-30 13:02 - 2016-09-15 17:54 - 00747520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Ocr.dll
2016-09-30 13:02 - 2016-09-15 17:54 - 00498688 _____ (Microsoft Corporation) C:\Windows\system32\mbsmsapi.dll
2016-09-30 13:02 - 2016-09-15 17:54 - 00493568 _____ (Microsoft Corporation) C:\Windows\system32\dsregcmd.exe
2016-09-30 13:02 - 2016-09-15 17:54 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2016-09-30 13:02 - 2016-09-15 17:54 - 00431104 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2016-09-30 13:02 - 2016-09-15 17:54 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
2016-09-30 13:02 - 2016-09-15 17:54 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
2016-09-30 13:02 - 2016-09-15 17:54 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Picker.dll
2016-09-30 13:02 - 2016-09-15 17:53 - 01344000 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2016-09-30 13:02 - 2016-09-15 17:53 - 00819200 _____ (Microsoft Corporation) C:\Windows\system32\AppContracts.dll
2016-09-30 13:02 - 2016-09-15 17:53 - 00466432 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll
2016-09-30 13:02 - 2016-09-15 17:53 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
2016-09-30 13:02 - 2016-09-15 17:53 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.dll
2016-09-30 13:02 - 2016-09-15 17:53 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00822272 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00525824 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00500736 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00298496 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2016-09-30 13:02 - 2016-09-15 17:52 - 00238080 _____ (Microsoft Corporation) C:\Windows\system32\AboveLockAppHost.dll
2016-09-30 13:02 - 2016-09-15 17:51 - 02333184 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2016-09-30 13:02 - 2016-09-15 17:51 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2016-09-30 13:02 - 2016-09-15 17:51 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2016-09-30 13:02 - 2016-09-15 17:51 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\CryptoWinRT.dll
2016-09-30 13:02 - 2016-09-15 17:50 - 01534464 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.3D.dll
2016-09-30 13:02 - 2016-09-15 17:50 - 00796672 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2016-09-30 13:02 - 2016-09-15 17:50 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\pwrshplugin.dll
2016-09-30 13:02 - 2016-09-15 17:50 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2016-09-30 13:02 - 2016-09-15 17:49 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2016-09-30 13:02 - 2016-09-15 17:49 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.InkControls.dll
2016-09-30 13:02 - 2016-09-15 17:48 - 01321472 _____ (Microsoft Corporation) C:\Windows\system32\wsp_fs.dll
2016-09-30 13:02 - 2016-09-15 17:48 - 01112576 _____ (Microsoft Corporation) C:\Windows\system32\wsp_health.dll
2016-09-30 13:02 - 2016-09-15 17:48 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll
2016-09-30 13:02 - 2016-09-15 17:48 - 00153088 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-09-30 13:02 - 2016-09-15 17:47 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2016-09-30 13:02 - 2016-09-15 17:47 - 01077760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Editing.dll
2016-09-30 13:02 - 2016-09-15 17:47 - 00355328 _____ (Microsoft Corporation) C:\Windows\system32\RTMediaFrame.dll
2016-09-30 13:02 - 2016-09-15 17:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\RelPost.exe
2016-09-30 13:02 - 2016-09-15 17:47 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Energy.dll
2016-09-30 13:02 - 2016-09-15 17:46 - 03305984 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2016-09-30 13:02 - 2016-09-15 17:46 - 00945664 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2016-09-30 13:02 - 2016-09-15 17:46 - 00558080 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2016-09-30 13:02 - 2016-09-15 17:46 - 00471552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-09-30 13:02 - 2016-09-15 17:46 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
2016-09-30 13:02 - 2016-09-15 17:46 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll
2016-09-30 13:02 - 2016-09-15 17:45 - 02749440 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2016-09-30 13:02 - 2016-09-15 17:45 - 00470016 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-09-30 13:02 - 2016-09-15 17:45 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\manage-bde.exe
2016-09-30 13:02 - 2016-09-15 17:44 - 02153984 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll
2016-09-30 13:02 - 2016-09-15 17:44 - 00734208 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-09-30 13:02 - 2016-09-15 17:44 - 00582656 _____ (Microsoft Corporation) C:\Windows\system32\SpaceControl.dll
2016-09-30 13:02 - 2016-09-15 17:44 - 00494592 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2016-09-30 13:02 - 2016-09-15 17:44 - 00459776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Playback.MediaPlayer.dll
2016-09-30 13:02 - 2016-09-15 17:44 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\fveui.dll
2016-09-30 13:02 - 2016-09-15 17:44 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\discan.dll
2016-09-30 13:02 - 2016-09-15 17:44 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\MSAC3ENC.DLL
2016-09-30 13:02 - 2016-09-15 17:44 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\fvenotify.exe
2016-09-30 13:02 - 2016-09-15 17:44 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\Sens.dll
2016-09-30 13:02 - 2016-09-15 17:43 - 03520512 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2016-09-30 13:02 - 2016-09-15 17:43 - 03196416 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2016-09-30 13:02 - 2016-09-15 17:43 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll
2016-09-30 13:02 - 2016-09-15 17:43 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll
2016-09-30 13:02 - 2016-09-15 17:43 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll
2016-09-30 13:02 - 2016-09-15 17:43 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\bdeui.dll
2016-09-30 13:02 - 2016-09-15 17:42 - 01220608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
2016-09-30 13:02 - 2016-09-15 17:42 - 00719872 _____ (Microsoft Corporation) C:\Windows\system32\wsp_sr.dll
2016-09-30 13:02 - 2016-09-15 17:42 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\SpaceAgent.exe
2016-09-30 13:02 - 2016-09-15 17:42 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\BitLockerDeviceEncryption.exe
2016-09-30 13:02 - 2016-09-15 17:42 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\BackgroundMediaPolicy.dll
2016-09-30 13:02 - 2016-09-15 17:41 - 03733504 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2016-09-30 13:02 - 2016-09-15 17:41 - 00400384 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2016-09-30 13:02 - 2016-09-15 17:41 - 00357376 _____ (Microsoft Corporation) C:\Windows\system32\Geolocation.dll
2016-09-30 13:02 - 2016-09-15 17:40 - 02138112 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
2016-09-30 13:02 - 2016-09-15 17:40 - 01656320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Perception.dll
2016-09-30 13:02 - 2016-09-15 17:40 - 01247232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2016-09-30 13:02 - 2016-09-15 17:40 - 01170944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
2016-09-30 13:02 - 2016-09-15 17:40 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2016-09-30 13:02 - 2016-09-15 17:40 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Midi.dll
2016-09-30 13:02 - 2016-09-15 17:39 - 02740224 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2016-09-30 13:02 - 2016-09-15 17:39 - 01232384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Maps.dll
2016-09-30 13:02 - 2016-09-15 17:39 - 01170944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Phone.dll
2016-09-30 13:02 - 2016-09-15 17:39 - 01004544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2016-09-30 13:02 - 2016-09-15 17:39 - 00941568 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2016-09-30 13:02 - 2016-09-15 17:39 - 00827904 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2016-09-30 13:02 - 2016-09-15 17:39 - 00240640 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2016-09-30 13:02 - 2016-09-15 17:38 - 00691200 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2016-09-30 13:02 - 2016-09-15 17:38 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2016-09-30 13:02 - 2016-09-15 17:38 - 00620544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2016-09-30 13:02 - 2016-09-15 17:38 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-09-30 13:02 - 2016-09-15 17:38 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2016-09-30 13:02 - 2016-09-15 17:36 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\TpmCoreProvisioning.dll
2016-09-30 13:02 - 2016-09-15 17:35 - 01438720 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll
2016-09-30 13:02 - 2016-09-15 17:35 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2016-09-30 13:02 - 2016-09-15 17:35 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2016-09-30 13:02 - 2016-09-15 17:35 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\spaceman.exe
2016-09-30 13:02 - 2016-08-06 04:33 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\smphost.dll
2016-09-30 13:01 - 2016-09-15 18:36 - 00021344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cmimcext.sys
2016-09-30 13:01 - 2016-09-15 18:17 - 04311736 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-09-30 13:01 - 2016-09-15 18:17 - 00125792 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostBroker.dll
2016-09-30 13:01 - 2016-09-15 18:06 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
2016-09-30 13:01 - 2016-09-15 18:01 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\cmintegrator.dll
2016-09-30 13:01 - 2016-09-15 18:00 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Family.Client.dll
2016-09-30 13:01 - 2016-09-15 17:58 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\vmrdvcore.dll
2016-09-30 13:01 - 2016-09-15 17:58 - 00291840 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll
2016-09-30 13:01 - 2016-09-15 17:58 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\wlancfg.dll
2016-09-30 13:01 - 2016-09-15 17:58 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\Family.SyncEngine.dll
2016-09-30 13:01 - 2016-09-15 17:57 - 03716096 _____ (Microsoft Corporation) C:\Windows\system32\bootux.dll
2016-09-30 13:01 - 2016-09-15 17:56 - 00670208 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService.dll
2016-09-30 13:01 - 2016-09-15 17:56 - 00265728 _____ C:\Windows\system32\Windows.Perception.Stub.dll
2016-09-30 13:01 - 2016-09-15 17:55 - 00518144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2016-09-30 13:01 - 2016-09-15 17:55 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\NetworkCollectionAgent.dll
2016-09-30 13:01 - 2016-09-15 17:55 - 00277504 _____ (Microsoft Corporation) C:\Windows\system32\icsvcext.dll
2016-09-30 13:01 - 2016-09-15 17:52 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2016-09-30 13:01 - 2016-09-15 17:52 - 00834560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll
2016-09-30 13:01 - 2016-09-15 17:52 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2016-09-30 13:01 - 2016-09-15 17:52 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2016-09-30 13:01 - 2016-09-15 17:50 - 07625728 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2016-09-30 13:01 - 2016-09-15 17:46 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2016-09-30 13:01 - 2016-09-15 17:45 - 02642944 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2016-09-30 13:01 - 2016-09-15 17:45 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\fvecpl.dll
2016-09-30 13:01 - 2016-09-15 17:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\dlnashext.dll
2016-09-30 13:01 - 2016-09-15 17:43 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\fvewiz.dll
2016-09-30 13:01 - 2016-09-15 17:43 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\PlayToReceiver.dll
2016-09-30 13:01 - 2016-09-15 17:40 - 02026496 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-09-30 13:01 - 2016-09-15 17:40 - 01988096 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2016-09-30 13:01 - 2016-09-15 17:38 - 00773120 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2016-09-29 14:34 - 2016-09-29 14:34 - 00000000 ____D C:\Users\chann\AppData\Local\CEF
2016-09-29 14:30 - 2016-09-29 14:30 - 00921280 _____ (Microsoft Corporation) C:\Windows\ucrtbase.dll
2016-09-29 14:29 - 2016-10-22 12:54 - 00000000 ____D C:\ProgramData\AVAST Software
2016-09-29 14:29 - 2016-09-29 14:29 - 06334656 _____ (AVAST Software) C:\Users\chann\Downloads\avast_free_antivirus_setup_online.exe
2016-09-29 13:46 - 2016-09-29 13:46 - 00000747 _____ C:\Users\chann\Desktop\Pictures - Shortcut.lnk
2016-09-29 13:42 - 2016-09-30 19:31 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-09-29 13:42 - 2016-09-29 13:42 - 00001133 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-09-29 13:42 - 2016-09-29 13:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-09-29 13:42 - 2016-09-29 13:42 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-09-29 13:42 - 2016-09-29 13:42 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2016-09-29 13:42 - 2016-03-10 14:09 - 00053120 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-09-29 13:42 - 2016-03-10 14:08 - 00126336 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-09-29 13:42 - 2016-03-10 14:08 - 00024448 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-09-29 13:08 - 2016-09-29 13:08 - 00000000 ____D C:\Users\chann\AppData\Roaming\Skype
2016-09-29 12:48 - 2016-09-29 12:48 - 00000754 _____ C:\Users\chann\Desktop\Documents.lnk
2016-09-29 11:34 - 2016-10-24 13:07 - 00000000 ____D C:\Program Files\SpeedFan
2016-09-29 11:34 - 2016-09-29 11:34 - 00001038 _____ C:\Users\chann\Desktop\SpeedFan.lnk
2016-09-29 11:34 - 2016-09-29 11:34 - 00000045 _____ C:\Windows\system32\initdebug.nfo
2016-09-29 11:34 - 2016-09-29 11:34 - 00000000 ____D C:\Users\chann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
2016-09-29 10:38 - 2016-09-29 10:38 - 00000000 ____D C:\Users\chann\Downloads\Pointing Driver Synaptics 9.1A_9.1.13.0
2016-09-29 10:37 - 2016-09-29 10:37 - 05311752 _____ C:\Users\chann\Downloads\Pointing Driver Synaptics 9.1A_9.1.13.0.zip
2016-09-29 09:56 - 2016-09-29 09:56 - 00000047 _____ C:\Users\chann\AppData\Roaming\WB.CFG
2016-09-28 21:45 - 2016-09-28 12:51 - 00000000 ____D C:\Windows\Panther
2016-09-28 16:52 - 2016-09-28 16:52 - 00000000 ____D C:\Users\chann\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
2016-09-28 16:33 - 2016-10-03 21:09 - 00828408 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-09-28 16:33 - 2016-10-03 21:09 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-09-28 16:02 - 2016-09-28 15:44 - 00406184 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-09-28 15:57 - 2016-10-11 21:35 - 00000000 ____D C:\Windows\system32\MRT
2016-09-28 15:57 - 2016-10-11 21:28 - 141042968 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-09-28 15:56 - 2016-09-07 06:37 - 01966288 _____ (Microsoft Corporation) C:\Windows\system32\hevcdecoder.dll
2016-09-28 15:56 - 2016-09-07 06:35 - 00315736 _____ (Microsoft Corporation) C:\Windows\system32\wifitask.exe
2016-09-28 15:56 - 2016-09-07 06:13 - 01557296 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2016-09-28 15:56 - 2016-09-07 05:55 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\wificonnapi.dll
2016-09-28 15:56 - 2016-09-07 05:52 - 00392704 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2016-09-28 15:56 - 2016-09-07 05:51 - 06534656 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
2016-09-28 15:56 - 2016-09-07 05:46 - 01013248 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2016-09-28 15:56 - 2016-09-07 05:35 - 01056768 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
2016-09-28 15:56 - 2016-09-07 05:34 - 04557824 _____ (Microsoft) C:\Windows\system32\dbgeng.dll
2016-09-28 15:56 - 2016-09-07 05:32 - 01556992 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2016-09-28 15:56 - 2016-09-07 05:31 - 01293312 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
2016-09-28 15:56 - 2016-09-07 05:31 - 00461312 _____ (Microsoft) C:\Windows\system32\DbgModel.dll
2016-09-28 15:56 - 2016-08-20 06:14 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2016-09-28 15:56 - 2016-08-20 06:04 - 00592384 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2016-09-28 15:56 - 2016-08-20 06:00 - 00141824 _____ (Windows ® Win 7 DDK provider) C:\Windows\system32\DscCoreConfProv.dll
2016-09-28 15:56 - 2016-08-06 04:44 - 00188928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2016-09-28 15:56 - 2016-08-06 04:39 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\DscCore.dll
2016-09-28 15:56 - 2016-08-02 05:47 - 00094528 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll
2016-09-28 15:56 - 2016-08-02 05:36 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-09-28 15:55 - 2016-09-07 06:33 - 00102752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-09-28 15:55 - 2016-09-07 06:32 - 02206496 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2016-09-28 15:55 - 2016-09-07 06:30 - 00601200 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2016-09-28 15:55 - 2016-09-07 06:29 - 01957216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2016-09-28 15:55 - 2016-09-07 06:27 - 01362504 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2016-09-28 15:55 - 2016-09-07 06:25 - 00133296 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-09-28 15:55 - 2016-09-07 06:17 - 00782176 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2016-09-28 15:55 - 2016-09-07 06:17 - 00509792 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2016-09-28 15:55 - 2016-09-07 06:16 - 00589144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ClipSp.sys
2016-09-28 15:55 - 2016-09-07 06:16 - 00399712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-09-28 15:55 - 2016-09-07 06:13 - 01853232 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2016-09-28 15:55 - 2016-09-07 06:13 - 00529928 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-09-28 15:55 - 2016-09-07 06:12 - 00321792 _____ (Microsoft Corporation) C:\Windows\system32\LockAppHost.exe
2016-09-28 15:55 - 2016-09-07 06:07 - 00043944 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-09-28 15:55 - 2016-09-07 06:00 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MosTrace.dll
2016-09-28 15:55 - 2016-09-07 06:00 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MosHost.dll
2016-09-28 15:55 - 2016-09-07 05:59 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\MosResource.dll
2016-09-28 15:55 - 2016-09-07 05:59 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft-Windows-MapControls.dll
2016-09-28 15:55 - 2016-09-07 05:59 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\ExtrasXmlParser.dll
2016-09-28 15:55 - 2016-09-07 05:59 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\MapControlStringsRes.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\MapsCSP.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\MosHostClient.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\POSyncServices.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\AddressParser.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTypeHelperUtil.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\UserDataLanguageUtil.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\nativemap.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\MapsBtSvcProxy.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\UserDataAccessRes.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\PhoneutilRes.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\PhoneServiceRes.dll
2016-09-28 15:55 - 2016-09-07 05:58 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2016-09-28 15:55 - 2016-09-07 05:57 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\ExSMime.dll
2016-09-28 15:55 - 2016-09-07 05:57 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-09-28 15:55 - 2016-09-07 05:56 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\MapsBtSvc.dll
2016-09-28 15:55 - 2016-09-07 05:56 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\MediaFoundation.DefaultPerceptionProvider.dll
2016-09-28 15:55 - 2016-09-07 05:56 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\ContactActivation.dll
2016-09-28 15:55 - 2016-09-07 05:55 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\VCardParser.dll
2016-09-28 15:55 - 2016-09-07 05:55 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-09-28 15:55 - 2016-09-07 05:55 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\MosStorage.dll
2016-09-28 15:55 - 2016-09-07 05:55 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\mapsupdatetask.dll
2016-09-28 15:55 - 2016-09-07 05:54 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2016-09-28 15:55 - 2016-09-07 05:54 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\moshost.dll
2016-09-28 15:55 - 2016-09-07 05:54 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\UserDataPlatformHelperUtil.dll
2016-09-28 15:55 - 2016-09-07 05:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\mapstoasttask.dll
2016-09-28 15:55 - 2016-09-07 05:53 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
2016-09-28 15:55 - 2016-09-07 05:53 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentActivation.dll
2016-09-28 15:55 - 2016-09-07 05:52 - 00536576 _____ (Microsoft Corporation) C:\Windows\system32\BingOnlineServices.dll
2016-09-28 15:55 - 2016-09-07 05:52 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
2016-09-28 15:55 - 2016-09-07 05:52 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\NmaDirect.dll
2016-09-28 15:55 - 2016-09-07 05:52 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\moshostcore.dll
2016-09-28 15:55 - 2016-09-07 05:50 - 00866816 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Cred.dll
2016-09-28 15:55 - 2016-09-07 05:50 - 00636928 _____ (Microsoft Corporation) C:\Windows\system32\PhoneService.dll
2016-09-28 15:55 - 2016-09-07 05:50 - 00582144 _____ (Microsoft Corporation) C:\Windows\system32\PhoneProviders.dll
2016-09-28 15:55 - 2016-09-07 05:50 - 00426496 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-09-28 15:55 - 2016-09-07 05:49 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-09-28 15:55 - 2016-09-07 05:49 - 00260096 _____ (Microsoft Corporation) C:\Windows\system32\Phoneutil.dll
2016-09-28 15:55 - 2016-09-07 05:47 - 02318336 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-09-28 15:55 - 2016-09-07 05:47 - 00340480 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-09-28 15:55 - 2016-09-07 05:46 - 01774080 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2016-09-28 15:55 - 2016-09-07 05:46 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
2016-09-28 15:55 - 2016-09-07 05:46 - 00838144 _____ (Microsoft Corporation) C:\Windows\system32\JpMapControl.dll
2016-09-28 15:55 - 2016-09-07 05:46 - 00755200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-09-28 15:55 - 2016-09-07 05:45 - 01228288 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2016-09-28 15:55 - 2016-09-07 05:44 - 01842688 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2016-09-28 15:55 - 2016-09-07 05:44 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\SensorDataService.exe
2016-09-28 15:55 - 2016-09-07 05:43 - 00342528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2016-09-28 15:55 - 2016-09-07 05:43 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-09-28 15:55 - 2016-09-07 05:39 - 05376000 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2016-09-28 15:55 - 2016-09-07 05:39 - 00895488 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2016-09-28 15:55 - 2016-09-07 05:39 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2016-09-28 15:55 - 2016-09-07 05:37 - 00640000 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2016-09-28 15:55 - 2016-09-07 05:36 - 02360832 _____ (Microsoft Corporation) C:\Windows\system32\MapRouter.dll
2016-09-28 15:55 - 2016-09-07 05:35 - 02107392 _____ (Microsoft Corporation) C:\Windows\system32\MapGeocoder.dll
2016-09-28 15:55 - 2016-09-07 05:35 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
2016-09-28 15:55 - 2016-09-07 05:34 - 03595264 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2016-09-28 15:55 - 2016-09-07 05:34 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-09-28 15:55 - 2016-09-07 05:34 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-09-28 15:55 - 2016-09-07 05:34 - 00860672 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2016-09-28 15:55 - 2016-09-07 05:34 - 00761344 _____ (Microsoft Corporation) C:\Windows\system32\NMAA.dll
2016-09-28 15:55 - 2016-09-07 05:34 - 00715264 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll
2016-09-28 15:55 - 2016-09-07 05:34 - 00444416 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2016-09-28 15:55 - 2016-08-27 05:58 - 00121368 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-09-28 15:55 - 2016-08-27 05:37 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\FSClient.dll
2016-09-28 15:55 - 2016-08-20 06:49 - 00092000 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2016-09-28 15:55 - 2016-08-20 06:15 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-09-28 15:55 - 2016-08-20 06:14 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll
2016-09-28 15:55 - 2016-08-20 06:14 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\BarcodeProvisioningPlugin.dll
2016-09-28 15:55 - 2016-08-20 06:14 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\RemovableMediaProvisioningPlugin.dll
2016-09-28 15:55 - 2016-08-20 06:12 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2016-09-28 15:55 - 2016-08-20 06:12 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\NFCProvisioningPlugin.dll
2016-09-28 15:55 - 2016-08-20 06:12 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll
2016-09-28 15:55 - 2016-08-20 06:12 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\provtool.exe
2016-09-28 15:55 - 2016-08-20 06:11 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll
2016-09-28 15:55 - 2016-08-20 06:11 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2016-09-28 15:55 - 2016-08-20 06:11 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManagerSvc.dll
2016-09-28 15:55 - 2016-08-20 06:09 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2016-09-28 15:55 - 2016-08-20 06:09 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2016-09-28 15:55 - 2016-08-20 06:09 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\provdatastore.dll
2016-09-28 15:55 - 2016-08-20 06:08 - 00392704 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2016-09-28 15:55 - 2016-08-20 06:06 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-09-28 15:55 - 2016-08-20 06:04 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2016-09-28 15:55 - 2016-08-20 06:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
2016-09-28 15:55 - 2016-08-20 05:58 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi_passthru.dll
2016-09-28 15:55 - 2016-08-20 05:56 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\delegatorprovider.dll
2016-09-28 15:55 - 2016-08-06 05:26 - 00036704 _____ (Microsoft Corporation) C:\Windows\system32\SysResetErr.exe
2016-09-28 15:55 - 2016-08-06 05:22 - 00173408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wof.sys
2016-09-28 15:55 - 2016-08-06 05:16 - 00798504 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-09-28 15:55 - 2016-08-06 05:15 - 00292184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2016-09-28 15:55 - 2016-08-06 05:14 - 00145248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-09-28 15:55 - 2016-08-06 05:08 - 00313560 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2016-09-28 15:55 - 2016-08-06 05:07 - 00520192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-09-28 15:55 - 2016-08-06 05:06 - 00023776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-09-28 15:55 - 2016-08-06 05:03 - 01343928 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2016-09-28 15:55 - 2016-08-06 05:03 - 00036168 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-09-28 15:55 - 2016-08-06 04:50 - 02755584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-09-28 15:55 - 2016-08-06 04:49 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.exe
2016-09-28 15:55 - 2016-08-06 04:48 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
2016-09-28 15:55 - 2016-08-06 04:48 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\WiFiConfigSP.dll
2016-09-28 15:55 - 2016-08-06 04:48 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-09-28 15:55 - 2016-08-06 04:48 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2016-09-28 15:55 - 2016-08-06 04:48 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2016-09-28 15:55 - 2016-08-06 04:48 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2016-09-28 15:55 - 2016-08-06 04:48 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2016-09-28 15:55 - 2016-08-06 04:47 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\dasHost.exe
2016-09-28 15:55 - 2016-08-06 04:47 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModelOOBE.exe
2016-09-28 15:55 - 2016-08-06 04:47 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\StorageUsage.dll
2016-09-28 15:55 - 2016-08-06 04:46 - 09260032 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2016-09-28 15:55 - 2016-08-06 04:45 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_WorkAccess.dll
2016-09-28 15:55 - 2016-08-06 04:45 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\wfdprov.dll
2016-09-28 15:55 - 2016-08-06 04:45 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-09-28 15:55 - 2016-08-06 04:45 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netiougc.exe
2016-09-28 15:55 - 2016-08-06 04:45 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\wlansvcpal.dll
2016-09-28 15:55 - 2016-08-06 04:44 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-09-28 15:55 - 2016-08-06 04:44 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\deviceassociation.dll
2016-09-28 15:55 - 2016-08-06 04:43 - 00395264 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2016-09-28 15:55 - 2016-08-06 04:43 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2016-09-28 15:55 - 2016-08-06 04:43 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\wifiprofilessettinghandler.dll
2016-09-28 15:55 - 2016-08-06 04:40 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModel.dll
2016-09-28 15:55 - 2016-08-06 04:40 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
2016-09-28 15:55 - 2016-08-06 04:39 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-09-28 15:55 - 2016-08-06 04:39 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll
2016-09-28 15:55 - 2016-08-06 04:37 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\das.dll
2016-09-28 15:55 - 2016-08-06 04:37 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-09-28 15:55 - 2016-08-06 04:37 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\indexeddbserver.dll
2016-09-28 15:55 - 2016-08-06 04:32 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2016-09-28 15:55 - 2016-08-06 04:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\wpninprc.dll
2016-09-28 15:55 - 2016-08-06 04:25 - 01997824 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2016-09-28 15:55 - 2016-08-06 04:25 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2016-09-28 15:55 - 2016-08-06 04:23 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\w32time.dll
2016-09-28 15:55 - 2016-08-06 04:21 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\offlinelsa.dll
2016-09-28 15:55 - 2016-08-05 10:10 - 00939872 _____ (Microsoft Corporation) C:\Windows\system32\pidgenx.dll
2016-09-28 15:55 - 2016-08-05 09:54 - 00564488 _____ (Microsoft Corporation) C:\Windows\system32\GenValObj.exe
2016-09-28 15:55 - 2016-08-05 09:29 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\slcext.dll
2016-09-28 15:55 - 2016-08-05 09:23 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2016-09-28 15:55 - 2016-08-05 09:18 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\slc.dll
2016-09-28 15:55 - 2016-08-02 05:37 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll
2016-09-28 15:55 - 2016-08-02 05:33 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.Search.UriHandler.dll
2016-09-28 15:55 - 2016-08-02 05:26 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Bluetooth.dll
2016-09-28 15:55 - 2016-07-22 02:11 - 01344992 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2016-09-28 15:55 - 2016-07-22 01:56 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2016-09-28 15:54 - 2016-09-07 06:29 - 00341344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2016-09-28 15:54 - 2016-09-07 06:25 - 00260448 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-09-28 15:54 - 2016-09-07 06:15 - 02166232 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2016-09-28 15:54 - 2016-09-07 06:13 - 00959104 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-09-28 15:54 - 2016-09-07 06:13 - 00432328 _____ (Microsoft Corporation) C:\Windows\system32\DMRServer.dll
2016-09-28 15:54 - 2016-09-07 06:13 - 00101216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\EhStorTcgDrv.sys
2016-09-28 15:54 - 2016-09-07 05:58 - 01631232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2016-09-28 15:54 - 2016-09-07 05:57 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-09-28 15:54 - 2016-09-07 05:54 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\tzautoupdate.dll
2016-09-28 15:54 - 2016-09-07 05:52 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2016-09-28 15:54 - 2016-09-07 05:50 - 01755136 _____ (Microsoft Corporation) C:\Windows\system32\DeviceFlows.DataModel.dll
2016-09-28 15:54 - 2016-09-07 05:49 - 13867520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2016-09-28 15:54 - 2016-09-07 05:46 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-09-28 15:54 - 2016-09-07 05:45 - 05398016 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll
2016-09-28 15:54 - 2016-09-07 05:40 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2016-09-28 15:54 - 2016-09-07 05:36 - 02423296 _____ (Microsoft Corporation) C:\Windows\system32\MSAJApi.dll
2016-09-28 15:54 - 2016-09-07 05:35 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-09-28 15:54 - 2016-09-07 05:34 - 01993216 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2016-09-28 15:54 - 2016-09-07 05:34 - 00920576 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2016-09-28 15:54 - 2016-09-07 05:30 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-09-28 15:54 - 2016-08-27 05:43 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\encapi.dll
2016-09-28 15:54 - 2016-08-20 06:44 - 00570720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2016-09-28 15:54 - 2016-08-20 06:15 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xinputhid.sys
2016-09-28 15:54 - 2016-08-20 06:14 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\C_G18030.DLL
2016-09-28 15:54 - 2016-08-20 06:14 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\C_IS2022.DLL
2016-09-28 15:54 - 2016-08-20 06:14 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\c_GSM7.DLL
2016-09-28 15:54 - 2016-08-20 06:08 - 00358912 _____ (Microsoft Corporation) C:\Windows\system32\facecredentialprovider.dll
2016-09-28 15:54 - 2016-08-20 06:07 - 00288768 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll
2016-09-28 15:54 - 2016-08-20 06:01 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
2016-09-28 15:54 - 2016-08-20 05:59 - 00079872 _____ (Microsoft Corporation) C:\Windows\system32\CastLaunch.dll
2016-09-28 15:54 - 2016-08-20 05:54 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\D3D12.dll
2016-09-28 15:54 - 2016-08-09 03:13 - 00162850 _____ C:\Windows\system32\C_932.NLS
2016-09-28 15:54 - 2016-08-06 04:59 - 00127168 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-09-28 15:54 - 2016-08-06 04:47 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2016-09-28 15:54 - 2016-08-06 04:47 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2016-09-28 15:54 - 2016-08-06 04:46 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\dafpos.dll
2016-09-28 15:54 - 2016-08-06 04:45 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\container.dll
2016-09-28 15:54 - 2016-08-06 04:43 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2016-09-28 15:54 - 2016-08-06 04:41 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\CloudBackupSettings.dll
2016-09-28 15:54 - 2016-08-06 04:41 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2016-09-28 15:54 - 2016-08-06 04:37 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2016-09-28 15:54 - 2016-08-06 04:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-09-28 15:54 - 2016-07-22 02:26 - 00054624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2016-09-28 15:54 - 2016-07-22 02:18 - 00297552 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll
2016-09-28 14:02 - 2016-09-28 14:02 - 00002013 _____ C:\Users\chann\Desktop\CrystalDiskInfo.lnk
2016-09-28 14:02 - 2016-09-28 14:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2016-09-28 14:01 - 2016-09-28 14:02 - 00000000 ____D C:\Program Files\CrystalDiskInfo
2016-09-28 13:27 - 2016-10-24 13:06 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2016-09-28 13:27 - 2016-09-29 14:47 - 00001166 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-09-28 13:27 - 2016-09-29 14:47 - 00001166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-09-28 13:27 - 2016-09-28 15:07 - 00000000 ____D C:\Users\chann\AppData\Local\Mozilla
2016-09-28 13:27 - 2016-09-28 13:28 - 00000000 ____D C:\Users\chann\AppData\Roaming\Mozilla
2016-09-28 13:25 - 2016-09-29 14:48 - 00000000 ____D C:\Users\chann\AppData\Roaming\Gagukome
2016-09-28 13:19 - 2016-09-28 13:19 - 00000000 ____D C:\Users\chann\AppData\Roaming\Macromedia
2016-09-28 13:17 - 2016-09-28 13:17 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-09-28 13:17 - 2016-09-28 13:17 - 00000000 ____D C:\Program Files\MSBuild
2016-09-28 13:17 - 2016-05-25 11:03 - 00778936 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2016-09-28 13:17 - 2016-05-25 11:03 - 00103120 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2016-09-28 13:17 - 2016-05-25 11:03 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2016-09-28 13:15 - 2016-09-28 13:15 - 00002338 _____ C:\Users\chann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium.lnk
2016-09-28 13:15 - 2016-09-28 13:15 - 00000000 ____D C:\Users\chann\AppData\Local\chromium
2016-09-28 13:14 - 2016-09-29 14:48 - 00000000 ____D C:\Users\chann\AppData\Roaming\{AF239998-8A71-F4EE-E147-D33C3D952E02}
2016-09-28 13:14 - 2016-09-29 12:25 - 00000000 ____D C:\ProgramData\{C63C035F-4C7E-8999-CAB8-17DB50FA9C15}
2016-09-28 13:14 - 2016-09-28 13:25 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-09-28 13:14 - 2016-09-28 13:14 - 43374408 _____ C:\Users\chann\Downloads\firefox_en_uk.exe
2016-09-28 13:09 - 2016-09-28 14:04 - 00000000 ____D C:\Users\chann\AppData\Local\MicrosoftEdge
2016-09-28 13:08 - 2016-10-21 15:09 - 00000000 ___RD C:\Users\chann\OneDrive
2016-09-28 13:08 - 2016-09-29 13:10 - 00002367 _____ C:\Users\chann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-09-28 13:08 - 2016-09-28 13:08 - 00000000 ____D C:\Users\chann\AppData\Local\NetworkTiles
2016-09-28 13:07 - 2016-09-28 13:07 - 00000000 ____D C:\Users\chann\AppData\Local\Comms
2016-09-28 13:07 - 2016-09-28 13:07 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2016-09-28 13:06 - 2016-09-28 13:06 - 00001051 _____ C:\Users\chann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2016-09-28 13:06 - 2016-09-28 13:06 - 00000000 ____D C:\Users\chann\AppData\Local\Publishers
2016-09-28 13:05 - 2016-10-04 11:30 - 00000000 ____D C:\Users\chann\AppData\Roaming\Adobe
2016-09-28 13:05 - 2016-10-03 16:09 - 00000000 ____D C:\Users\chann\AppData\Local\Packages
2016-09-28 13:05 - 2016-10-02 17:02 - 00000000 ____D C:\Users\chann\AppData\Local\VirtualStore
2016-09-28 13:05 - 2016-09-30 13:17 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-09-28 13:05 - 2016-09-28 13:45 - 00000000 ____D C:\Users\chann\AppData\Local\ConnectedDevicesPlatform
2016-09-28 13:05 - 2016-09-28 13:05 - 00000000 ____D C:\Users\chann\AppData\Local\TileDataLayer
2016-09-28 13:04 - 2016-10-17 21:54 - 00000000 ____D C:\Users\chann
2016-09-28 13:04 - 2016-09-28 13:04 - 00000020 ___SH C:\Users\chann\ntuser.ini
2016-09-28 13:04 - 2016-09-28 13:04 - 00000000 _SHDL C:\Users\chann\My Documents
2016-09-28 13:04 - 2016-09-28 13:04 - 00000000 _SHDL C:\Users\chann\Documents\My Videos
2016-09-28 13:04 - 2016-09-28 13:04 - 00000000 _SHDL C:\Users\chann\Documents\My Pictures
2016-09-28 13:04 - 2016-09-28 13:04 - 00000000 _SHDL C:\Users\chann\Documents\My Music
2016-09-28 12:59 - 2016-09-28 12:59 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2016-09-28 12:59 - 2016-09-28 12:59 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2016-09-28 12:59 - 2016-09-28 12:59 - 00000000 ____D C:\Program Files\Synaptics
2016-09-28 12:59 - 2016-01-07 23:15 - 00035504 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\Smb_driver_Intel.sys
2016-09-28 12:57 - 2016-10-23 22:29 - 00820976 _____ C:\Windows\system32\PerfStringBackup.INI
2016-09-28 12:56 - 2016-09-28 12:58 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\Packages
2016-09-28 12:56 - 2016-09-28 12:56 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\VirtualStore
2016-09-28 12:56 - 2016-09-28 12:56 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\TileDataLayer
2016-09-28 12:56 - 2016-09-28 12:56 - 00000000 ____D C:\Users\defaultuser0\AppData\Local\ConnectedDevicesPlatform
2016-09-28 12:53 - 2016-09-28 12:53 - 00000020 ___SH C:\Users\defaultuser0\ntuser.ini
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 _SHDL C:\Users\Public\Documents\My Videos
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 _SHDL C:\Users\Public\Documents\My Pictures
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 _SHDL C:\Users\Public\Documents\My Music
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 _SHDL C:\Users\defaultuser0\My Documents
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Videos
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Pictures
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Music
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 _SHDL C:\Documents and Settings
2016-09-28 12:53 - 2016-09-28 12:53 - 00000000 ____D C:\Users\defaultuser0
2016-09-28 12:52 - 2016-09-28 12:52 - 00000000 _SHDL C:\Users\Default\My Documents
2016-09-28 12:52 - 2016-09-28 12:52 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2016-09-28 12:52 - 2016-09-28 12:52 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2016-09-28 12:52 - 2016-09-28 12:52 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2016-09-28 12:52 - 2016-09-28 12:52 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2016-09-28 12:52 - 2016-09-28 12:52 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2016-09-28 12:52 - 2016-09-28 12:52 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2016-09-28 12:48 - 2016-09-28 12:48 - 00000000 ____D C:\ProgramData\USOShared
2016-09-28 12:47 - 2016-10-24 11:57 - 00000000 ____D C:\Windows\system32\SleepStudy
2016-09-28 12:47 - 2016-10-23 22:24 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-09-28 12:47 - 2016-10-23 20:20 - 00261696 _____ C:\Windows\system32\FNTCACHE.DAT
2016-09-28 12:47 - 2016-09-28 12:47 - 00000000 ____D C:\Windows\ServiceProfiles
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-10-23 22:24 - 2016-07-16 03:22 - 00524288 _____ C:\Windows\system32\config\BBI
2016-10-23 20:28 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\AppReadiness
2016-10-23 20:16 - 2016-07-16 09:19 - 00000000 ____D C:\Windows\CbsTemp
2016-10-22 11:09 - 2016-07-16 09:29 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2016-10-21 15:46 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\LiveKernelReports
2016-10-21 15:45 - 2016-07-16 09:28 - 00000000 ____D C:\Windows\INF
2016-10-21 11:39 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\NDF
2016-10-21 10:10 - 2016-07-16 09:29 - 00000000 ___HD C:\Program Files\WindowsApps
2016-10-20 10:22 - 2016-07-16 09:29 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-10-13 16:44 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\rescache
2016-10-11 22:04 - 2016-07-16 09:29 - 00000000 ___SD C:\Windows\system32\DiagSvcs
2016-10-11 22:04 - 2016-07-16 09:29 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2016-10-11 22:04 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2016-10-11 22:04 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\migwiz
2016-10-11 22:04 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\en-GB
2016-10-11 22:04 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\ShellExperiences
2016-10-11 22:04 - 2016-07-16 09:29 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-10-11 21:16 - 2016-07-16 09:25 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Diagnostics.dll
2016-10-03 21:47 - 2016-07-16 11:15 - 00000000 ____D C:\Windows\OCR
2016-10-03 21:39 - 2016-07-16 11:15 - 00000000 ____D C:\Windows\system32\WCN
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ___SD C:\Windows\system32\F12
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ___RD C:\Windows\MiracastView
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ___RD C:\Program Files\Windows Defender
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\oobe
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\PolicyDefinitions
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\IME
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\Help
2016-10-03 21:39 - 2016-07-16 09:29 - 00000000 ____D C:\Program Files\Common Files\System
2016-10-03 21:39 - 2016-07-16 03:22 - 00000000 ____D C:\Windows\servicing
2016-10-03 16:38 - 2016-07-16 09:29 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-10-02 17:20 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\System
2016-10-02 17:18 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\Registration
2016-09-30 15:09 - 2016-07-16 09:30 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts_bak_673
2016-09-30 15:02 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\security
2016-09-30 14:42 - 2016-07-16 09:29 - 00000000 ___RD C:\Windows\PrintDialog
2016-09-30 13:11 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\setup
2016-09-30 13:11 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\appraiser
2016-09-30 13:11 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\Provisioning
2016-09-30 13:11 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\bcastdvr
2016-09-30 13:11 - 2016-07-16 03:22 - 00000000 ____D C:\Windows\system32\Sysprep
2016-09-30 13:11 - 2016-07-16 03:22 - 00000000 ____D C:\Windows\system32\Dism
2016-09-29 09:58 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\appcompat
2016-09-28 21:44 - 2016-07-16 09:30 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2016-09-28 16:28 - 2016-07-16 09:29 - 00000000 ___SD C:\Windows\system32\dsc
2016-09-28 16:28 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\lv-LV
2016-09-28 16:28 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\lt-LT
2016-09-28 16:28 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\et-EE
2016-09-28 16:28 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\es-MX
2016-09-28 13:04 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2016-09-28 12:55 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\spool
2016-09-28 12:55 - 2016-07-16 09:29 - 00000000 ____D C:\Windows\system32\FxsTmp
2016-09-28 12:48 - 2016-07-16 09:29 - 00000000 ____D C:\ProgramData\USOPrivate
2016-09-28 12:48 - 2016-07-16 03:22 - 00032768 _____ C:\Windows\system32\config\ELAM
==================== Files in the root of some directories =======
2016-09-29 09:56 - 2016-09-29 09:56 - 0000047 _____ () C:\Users\chann\AppData\Roaming\WB.CFG
2016-10-02 17:02 - 2016-10-02 17:02 - 0000000 _____ () C:\Users\chann\AppData\Roaming\wklnhst.dat
2016-10-24 10:22 - 2016-10-24 10:22 - 1115164 _____ () C:\Users\chann\AppData\Local\ars.cache
2016-10-24 10:24 - 2016-10-24 10:24 - 0865841 _____ () C:\Users\chann\AppData\Local\census.cache
2016-10-24 09:59 - 2016-10-24 09:59 - 0000036 _____ () C:\Users\chann\AppData\Local\housecall.guid.cache
2016-10-24 10:11 - 2016-10-24 10:11 - 0000010 _____ () C:\Users\chann\AppData\Local\sponge.last.runtime.cache
Some files in TEMP:
====================
C:\Users\chann\AppData\Local\Temp\sfamcc00001.dll

==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-10-20 10:24
==================== End of FRST.txt ============================
 
 
 
 
 
 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 16-10-2016
Ran by chann (24-10-2016 15:05:58)
Running from C:\Users\chann\Desktop
Microsoft Windows 10 Home Version 1607 (X86) (2016-09-28 11:56:30)
Boot Mode: Normal
==========================================================

==================== Accounts: =============================
Administrator (S-1-5-21-2764644833-1114247620-3834938357-500 - Administrator - Disabled)
chann (S-1-5-21-2764644833-1114247620-3834938357-1001 - Administrator - Enabled) => C:\Users\chann
DefaultAccount (S-1-5-21-2764644833-1114247620-3834938357-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-2764644833-1114247620-3834938357-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-2764644833-1114247620-3834938357-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-2764644833-1114247620-3834938357-1004 - Limited - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20039 - Adobe Systems Incorporated)
CCleaner (HKLM\...\CCleaner) (Version: 5.23 - Piriform)
CrystalDiskInfo 7.0.3 (HKLM\...\CrystalDiskInfo_is1) (Version: 7.0.3 - Crystal Dew World)
Google Chrome (HKLM\...\Google Chrome) (Version: 53.0.2785.143 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.31.5 - Google Inc.) Hidden
gpedt.msc 1.0 (HKLM\...\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version:  - Richard)
HouseCall for Home Networks (HKLM\...\DRScanner) (Version: 2.0.0.1138 - Trend Micro Inc.)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office Home and Student 2013 - en-us (HKLM\...\HomeStudentRetail - en-us) (Version: 15.0.4867.1003 - Microsoft Corporation)
Mozilla Firefox 49.0.2 (x86 en-GB) (HKLM\...\Mozilla Firefox 49.0.2 (x86 en-GB)) (Version: 49.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 49.0.2.6136 - Mozilla)
Office 15 Click-to-Run Extensibility Component (Version: 15.0.4867.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4867.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (Version: 15.0.4867.1003 - Microsoft Corporation) Hidden
Opera Stable 40.0.2308.90 (HKLM\...\Opera 40.0.2308.90) (Version: 40.0.2308.90 - Opera Software)
SpeedFan (remove only) (HKLM\...\SpeedFan) (Version:  - )
Spotify (HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\...\Spotify) (Version: 1.0.38.171.g5e1cd7b2 - Spotify AB)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.19.1 - Synaptics Incorporated)
Tweaking.com - Windows Repair (HKLM\...\Tweaking.com - Windows Repair) (Version: 3.9.13 - Tweaking.com)
WinPcap 4.1.3 (HKLM\...\WinPcapInst) (Version: 4.1.0.2980 - CACE Technologies)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0C973036-FAB2-41D2-8925-3BEF0947A9E3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX86\OfficeC2RClient.exe [2016-10-03] (Microsoft Corporation)
Task: {22EEE41C-C251-4EB1-9DC3-50AA0582E46D} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-12] (Tweaking.com)
Task: {2D39D3CF-8211-4DDF-A8E7-7DC1EB25B878} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX86\OfficeC2RClient.exe [2016-10-03] (Microsoft Corporation)
Task: {4AD94125-2634-4FEC-93A0-04171186F176} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-09-28] (Piriform Ltd)
Task: {59FA111B-F6E6-4DEA-98BC-A7BDC60144C4} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {5EED6350-6A42-479E-B4EF-40CA21433D3D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-10-04] (Google Inc.)
Task: {9264D2CC-83E0-43BB-8501-35B4FB7D1E6E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-10-04] (Google Inc.)
Task: {9338BF3F-E9CC-4C69-A386-CEB91E7AB0D9} - System32\Tasks\Opera scheduled Autoupdate 1475329204 => C:\Program Files\Opera\launcher.exe [2016-10-17] (Opera Software)
Task: {AA8D2E35-4040-435A-8C74-85F6D6A1C4C3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {AFE019F2-0587-465A-BCA7-11C912BBE7CF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
Task: {B8D6A592-01CD-40C6-A467-F3751D8FA419} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {C6045F48-0DFB-4A5D-9F04-F9D4EDDF5D1E} - System32\Tasks\DRScanner Startup => C:\Program Files\Trend Micro\DRScanner\DRScanner.exe [2016-07-13] (Trend Micro Inc.)
Task: {C8E3A1A0-4D12-4A14-96B7-9CE0AB7ADEE6} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation)
Task: {F3C0E8D1-DB3D-4FAA-A2A4-251931BF0AA4} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\chann\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe [2016-09-29] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2013-02-01 15:54 - 2013-02-01 15:54 - 12875264 _____ () C:\Windows\system32\spool\DRIVERS\W32X86\3\dlthm1zRC.DLL
2016-10-03 16:29 - 2016-05-24 08:21 - 00089792 _____ () C:\Program Files\Microsoft Office 15\ClientX86\ApiClient.dll
2016-07-16 09:25 - 2016-07-16 09:25 - 00190976 _____ () C:\Windows\SYSTEM32\ism32k.dll
2016-09-30 13:02 - 2016-09-15 18:32 - 02048496 _____ () C:\Windows\System32\CoreUIComponents.dll
2016-09-30 13:02 - 2016-09-15 18:32 - 02048496 _____ () C:\Windows\system32\CoreUIComponents.dll
2016-09-30 13:02 - 2016-09-15 18:32 - 02048496 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll
2016-09-29 13:08 - 2016-09-29 13:08 - 01383616 _____ () C:\Users\chann\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\ClientTelemetry.dll
2016-07-16 09:25 - 2016-07-16 09:25 - 00109056 _____ () C:\Windows\SYSTEM32\CHARTV.dll
2016-07-16 09:25 - 2016-07-16 09:25 - 00108032 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2016-09-28 15:55 - 2016-08-06 04:43 - 00321536 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2016-10-11 21:24 - 2016-10-05 10:10 - 06726656 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-10-11 21:24 - 2016-10-05 10:06 - 01149440 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-09-28 15:54 - 2016-08-06 04:21 - 00526848 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2016-10-11 21:24 - 2016-10-05 10:05 - 00779776 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-10-11 21:24 - 2016-10-05 10:05 - 01725440 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-10-11 21:24 - 2016-10-05 10:07 - 03158528 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-09-29 13:08 - 2016-09-29 13:09 - 00118976 _____ () C:\Users\chann\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\FileSyncViews.dll
2016-10-20 10:15 - 2016-10-20 10:15 - 00062464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x86__kzf8qxf38zg5c\SkypeHost.exe
2016-10-20 10:15 - 2016-10-20 10:15 - 00151040 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.8.197.0_x86__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)

==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)

==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2016-07-16 09:30 - 2016-10-23 19:56 - 00000855 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\chann\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 194.168.4.100 - 194.168.8.100
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{F2F34473-FA09-4FA8-B8D6-3593BBD4DBC4}] => (Allow) C:\Users\chann\AppData\Local\Chromium\Application\chrome.exe
FirewallRules: [{85CF7726-A56E-45FE-9CEB-A86F99AC82BE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{4ED19B8D-6D95-424E-AE12-3669EE3463B1}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{331ADA5F-72A0-45CE-8178-0C2E39BAD61B}C:\users\chann\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\chann\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{0903E50D-FB5A-47D2-BDA8-7764F8B33ABA}C:\users\chann\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\chann\appdata\roaming\spotify\spotify.exe
FirewallRules: [{B5CF23CD-C247-413A-8B77-EF6667DFCAF2}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [WMP-In-UDP-x86] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [WMP-Out-UDP-x86] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [WMP-Out-TCP-x86] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [{32C5DA6B-1D6F-4180-B061-9FC172558990}] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [{F6202490-FCD1-4887-BE3B-C2069D93760A}] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
FirewallRules: [{0BA1D169-BED8-4049-9560-1D95E04ECDE9}] => (Allow) %ProgramFiles(x86)%\Windows Media Player\wmplayer.exe
==================== Restore Points =========================
05-10-2016 12:53:28 Windows Modules Installer
11-10-2016 21:26:56 Windows Update
20-10-2016 10:24:54 Windows Update
23-10-2016 18:13:09 allinonerepair
==================== Faulty Device Manager Devices =============
Name: Base System Device
Description: Base System Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

==================== Event log errors: =========================
Application errors:
==================
Error: (10/24/2016 02:44:52 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\CrystalDiskInfo\DiskInfo64.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (10/24/2016 10:38:07 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\CrystalDiskInfo\DiskInfo64.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (10/24/2016 10:37:28 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\CrystalDiskInfo\DiskInfo64.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (10/23/2016 08:20:58 PM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Error while updating Windows Defender status to SECURITY_PRODUCT_STATE_SNOOZED (error %3).
Error: (10/23/2016 08:20:58 PM) (Source: SecurityCenter) (EventID: 16) (User: )
Description: Error while updating Windows Defender status to SECURITY_PRODUCT_STATE_SNOOZED (error %3).
Error: (10/23/2016 08:19:24 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 512) (User: )
Description: The Cryptographic Services service failed to initialise the VSS backup "System Writer" object.
Details:
Could not query the status of the EventSystem service.
System Error:
A system shutdown is in progress.
.
Error: (10/23/2016 08:17:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NEAL2-SONYVAIO)
Description: Installing the performance counter strings for service .NET CLR Data () failed. The first DWORD in the Data section contains the error code.
Error: (10/23/2016 08:17:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NEAL2-SONYVAIO)
Description: Installing the performance counter strings for service .NET CLR Networking () failed. The first DWORD in the Data section contains the error code.
Error: (10/23/2016 08:17:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NEAL2-SONYVAIO)
Description: Installing the performance counter strings for service .NET Data Provider for Oracle () failed. The first DWORD in the Data section contains the error code.
Error: (10/23/2016 08:17:00 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NEAL2-SONYVAIO)
Description: Installing the performance counter strings for service .NET Data Provider for SqlServer () failed. The first DWORD in the Data section contains the error code.

System errors:
=============
Error: (10/24/2016 10:45:56 AM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer NEAL1-DELL
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{270722F4-8789-46A3-BE70-3D8D385.
The master browser is stopping or an election is being forced.
Error: (10/23/2016 10:24:57 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (10/23/2016 08:20:27 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (10/23/2016 08:19:22 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "1084" attempting to start the service dps with arguments "Unavailable" in order to run the server:
{DDCFD26B-FEED-44CD-B71D-79487D2E5E5A}
Error: (10/23/2016 08:18:45 PM) (Source: DCOM) (EventID: 10005) (User: NEAL2-SONYVAIO)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
Error: (10/23/2016 08:18:30 PM) (Source: DCOM) (EventID: 10005) (User: NEAL2-SONYVAIO)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error: (10/23/2016 08:18:30 PM) (Source: DCOM) (EventID: 10005) (User: NEAL2-SONYVAIO)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error: (10/23/2016 08:18:29 PM) (Source: DCOM) (EventID: 10005) (User: NEAL2-SONYVAIO)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (10/23/2016 08:18:29 PM) (Source: DCOM) (EventID: 10005) (User: NEAL2-SONYVAIO)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
Error: (10/23/2016 08:18:29 PM) (Source: DCOM) (EventID: 10005) (User: NEAL2-SONYVAIO)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}

CodeIntegrity:
===================================
  Date: 2016-09-28 20:59:17.591
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\pmls.dll that did not meet the Store signing level requirements.
  Date: 2016-09-28 15:02:12.189
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\LogMeIn Rescue RC - fea802f8-e6ce-4175-ad09-474fd78263a6\LMIRhook.000.dll that did not meet the Store signing level requirements.
  Date: 2016-09-28 15:01:28.058
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\pmls.dll that did not meet the Store signing level requirements.
  Date: 2016-09-28 15:01:28.031
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\LogMeIn Rescue RC - fea802f8-e6ce-4175-ad09-474fd78263a6\LMIRhook.000.dll that did not meet the Store signing level requirements.
  Date: 2016-09-28 15:00:02.845
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\LogMeIn Rescue RC - fea802f8-e6ce-4175-ad09-474fd78263a6\LMIRhook.000.dll that did not meet the Store signing level requirements.
  Date: 2016-09-28 13:53:40.720
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\pmls.dll that did not meet the Store signing level requirements.
  Date: 2016-09-28 13:47:31.577
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\pmls.dll that did not meet the Store signing level requirements.

==================== Memory info ===========================
Processor: Intel® Pentium® Dual CPU T3400 @ 2.16GHz
Percentage of memory in use: 45%
Total physical RAM: 2939.03 MB
Available physical RAM: 1606.84 MB
Total Virtual: 3451.03 MB
Available Virtual: 1962.86 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:232.4 GB) (Free:208.79 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 9FC9D63D)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.4 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
 
 
 
 
 
 

Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 29/09/2016
Scan Time: 13:44
Logfile:
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.09.29.06
Rootkit Database: v2016.09.26.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x86
File System: NTFS
User: chann
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 287221
Time Elapsed: 7 min, 3 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 6
Trojan.Dropper, C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe, 640, Delete-on-Reboot, [1ad0fb7cd8c2db5b7279d812ef15916f]
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmservice.exe, 688, Delete-on-Reboot, [6d7de097643637fff5c158332dd3be42]
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmropn.exe, 3488, Delete-on-Reboot, [f4f6c9ae7e1cee484d69315aa45c748c]
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\5.5.5995.17222\winwb.exe, 4848, Delete-on-Reboot, [5298fd7a1189ff375bb6a922a85a966a]
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmropn.exe, 3488, Delete-on-Reboot, [99514c2b9604f343f3ac3f7ba55dc739]
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmservice.exe, 688, Delete-on-Reboot, [99514c2b9604f343f3ac3f7ba55dc739]
Modules: 23
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Registry Keys: 23
Trojan.Dropper, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rtop, Quarantined, [1ad0fb7cd8c2db5b7279d812ef15916f],
Adware.PremierOpinion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PremierOpinion, Quarantined, [6d7de097643637fff5c158332dd3be42],
Adware.PremierOpinion, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{eeb86aef-4a5d-4b75-9d74-f16d438fc286}, Quarantined, [f4f6c9ae7e1cee484d69315aa45c748c],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Quarantined, [846603743e5ca4921f454485877b58a8],
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\TRACING\winwb_RASAPI32, Quarantined, [effb7304a8f201355d2fc936c73ce818],
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\TRACING\winwb_RASMANCS, Quarantined, [6a8012653a6002342a6244bb24df7090],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{69801EAB-E5B0-482E-96A9-39CA65E560B2}, Delete-on-Reboot, [a54599de524849ed31eafeb606feaa56],
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B295E6A9-B93E-423E-8994-0F667B9ADD33}, Delete-on-Reboot, [c42680f7f7a382b488cdf80621e228d8],
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E262E9CB-7DA4-434F-823A-D943B97D5F63}, Delete-on-Reboot, [e00a562102986fc7b79e03fb778ce818],
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WBLaunchTask, Delete-on-Reboot, [9852e5928e0c93a360f6ea14db28827e],
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\WBUpdateTask, Delete-on-Reboot, [02e83740cfcbf14551050fef758e4db3],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Yahoo! Powered lodol, Delete-on-Reboot, [cf1b0c6be1b940f6b8647c38b64e6898],
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{0BCE8B0A-1E76-44E5-9909-3CF804D92E4D}_is1, Quarantined, [32b88ee9e4b6e551d04695677a894ab6],
PUP.Optional.WebBar, HKLM\SOFTWARE\WEBBAR, Quarantined, [e802383fd0ca8ea8ca4dcb318e7509f7],
PUP.Optional.InstallCore, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\csastats, Quarantined, [a14995e2c4d6e452067f4eacf310a759],
PUP.Optional.InstallCore, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\ICSW1.22, Quarantined, [0fdbadca3169a294f11bb2f5a65d3ac6],
PUP.Optional.WinYahoo, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Quarantined, [f3f73a3db7e3c07667fc29a00df5a35d],
PUP.Optional.WinYahoo, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2211D4A5-48D0-47F5-A7CD-81E861470F7F}, Quarantined, [0bdf90e79cfeaa8ce97acaffde24857b],
PUP.Optional.ProductSetup, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\PRODUCTSETUP, Quarantined, [0ddd6512afebda5c368b5a564ab9b050],
PUP.Optional.PremierOpinion, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{eeb86aef-4a5d-4b75-9d74-f16d438fc286}, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\PremierOpinion, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1BEBF32B-4B6B-22AB-FAEB-522B2A6B81AB}, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Chromium, Quarantined, [74760176c4d601355df6376619eb9868],
Registry Values: 14
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://uk.search.ya...arantinedBHome,%4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://uk.search.ya...={searchTerms},%4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{69801EAB-E5B0-482E-96A9-39CA65E560B2}|Path, \Yahoo! Powered lodol, Delete-on-Reboot, [a54599de524849ed31eafeb606feaa56]
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{B295E6A9-B93E-423E-8994-0F667B9ADD33}|Path, \WBUpdateTask, Delete-on-Reboot, [c42680f7f7a382b488cdf80621e228d8]
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E262E9CB-7DA4-434F-823A-D943B97D5F63}|Path, \WBLaunchTask, Delete-on-Reboot, [e00a562102986fc7b79e03fb778ce818]
PUP.Optional.WebBar, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WebBar Toolbar, C:\Program Files\WebBarMedia\5.5.5995.17222\winwb.exe, Quarantined, [5298fd7a1189ff375bb6a922a85a966a]
PUP.Optional.OpinionSquare, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}, C:\Program Files\PremierOpinion\firefox, Quarantined, [00eab2c58c0ede58c987347a0cf748b8]
PUP.Optional.WebBar, HKLM\SOFTWARE\WEBBAR|Wb, C:\Program Files\WebBarMedia\5.5.5995.17222\winwb.exe, Quarantined, [e802383fd0ca8ea8ca4dcb318e7509f7]
PUP.Optional.PremierOpinion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{6B65BB6F-D8D6-45F3-B25B-BB3ABF2C54DA}, v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\Program Files\PremierOpinion\pmropn.exe|Name=pmropn.exe|, Quarantined, [d7133a3da1f923138dbc2ebf48bb3dc3]
PUP.Optional.PremierOpinion, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES|{47A08AA6-50A5-410F-8FFE-426D9AC961F0}, v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\Program Files\PremierOpinion\pmropn.exe|Name=pmropn.exe|, Quarantined, [8763581fe7b3f73f2f1a3faef90a58a8]
PUP.Optional.WebBar, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|winwb.exe, 11000, Quarantined, [5694e295a7f37db9c94cbd3fde25827e]
PUP.Optional.WinYahoo, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://uk.search.ya...={searchTerms},%4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2211d4a5-48d0-47f5-a7cd-81e861470f7f}|URL, https://uk.search.ya...={searchTerms},%4, %5
PUP.Optional.ProductSetup, HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\PRODUCTSETUP|tb, 0G2O2W1R0C1R1H, Quarantined, [0ddd6512afebda5c368b5a564ab9b050]
Registry Data: 1
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://uk.search.ya...=1&param2=fBad:(https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]D1%26bBad: (https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]DIE%26ccBad: (https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]Dgb%26paBad: (https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]Dwincy%26cdBad: (https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]D2XzuyEtN2Y1L1QzutCtBtBtAyE0D0EtByD0Bzzzy0FtC0DyEtN0D0Tzu0StCyBtAtBtN1L2XzutAtFtByEtFtCyBtFyDyEtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StD0B0AyByCyEzztAtGtD0EtCyEtG0CyDyC0AtGtA0DzztDtGyDyCyEyDyEtBtB0D0CyByD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0CtA0Fzy0DyCtDtG0CyB0A0EtGyEtCtD0DtGzy0CyB0AtGyBtBtDtByD0E0AyDtBtD0Dzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDtC%26crBad: (https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]D1879745563%26aBad: (https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]Dwbf_ir_16_39%26os_verBad: (https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]D10.0%26osBad: (https://uk.search.ya...Windows+10+Home),Replaced,[83676314f0aad85e75ca90e926dece32]DWindowsGood: (www.google.com)B10Good: (www.google.com)BHome, %4, %5
Folders: 45
PUP.Optional.WebBar, C:\Users\chann\AppData\Local\WebBar, Delete-on-Reboot, [64861e5916842610f75fe0db5aa937c9],
PUP.Optional.WebBar, C:\Windows\System32\config\systemprofile\AppData\Local\WebBar, Quarantined, [d5150077faa078be81d6af0cf013ba46],
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion, Quarantined, [955595e26535bb7bfebb920cc14145bb],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion, Delete-on-Reboot, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\components, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\defaults, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\defaults\preferences, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\addon, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\dom, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\lang, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\net, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\platform, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\preferences, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\window, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\toolkit, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\dpjs, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\dpjs\data, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\dpjs\lib, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Users\chann\AppData\Local\Temp\PremierOpinion, Quarantined, [72780e694951b4829f019a202dd5e11f],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia, Delete-on-Reboot, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\5.5.5995.17222, Delete-on-Reboot, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}, Quarantined, [74760176c4d601355df6376619eb9868],
Files: 170
Adware.PremierOpinion, C:\Windows\System32\pmls.dll, Delete-on-Reboot, [7b6fc9ae4f4b60d62e8893f80af604fc],
Trojan.Dropper, C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe, Delete-on-Reboot, [1ad0fb7cd8c2db5b7279d812ef15916f],
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmservice.exe, Delete-on-Reboot, [6d7de097643637fff5c158332dd3be42],
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmropn.exe, Delete-on-Reboot, [f4f6c9ae7e1cee484d69315aa45c748c],
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmropn32.exe, Delete-on-Reboot, [effbff78e1b950e6a41289020ff1c040],
PUP.Optional.InstallCore, C:\ProgramData\Microsoft\Windows Defender\Scans\FilesStash\245284FD-E808-DE0D-17B9-606F4F13E30E_1d21a4ad187a6ac, Quarantined, [975372059604a393ce9d003bce33b34d],
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmls.dll, Quarantined, [9357afc8d5c5e84e219543487f81a858],
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmls64.dll, Quarantined, [23c7f087debca096caec9bf0966a47b9],
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmph.dll, Quarantined, [d515f483207a4ee8a4127318ef1103fd],
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmropn64.exe, Quarantined, [6a80beb92773bc7ac1f5177404fccd33],
Adware.PremierOpinion, C:\Program Files\PremierOpinion\pmxf.dll, Quarantined, [07e3bfb86733a591d8de29621fe12ed2],
PUP.Optional.InstallCore, C:\Users\chann\Downloads\firefox_download.exe, Quarantined, [edfd9cdb4951fa3cf9720e2d679a758b],
PUP.Optional.WebBar, C:\Users\chann\AppData\Local\WebBar\wb.app.settings, Quarantined, [64861e5916842610f75fe0db5aa937c9],
PUP.Optional.WebBar, C:\Users\chann\AppData\Local\WebBar\wb.log, Delete-on-Reboot, [64861e5916842610f75fe0db5aa937c9],
PUP.Optional.WebBar, C:\Users\chann\AppData\Local\WebBar\wb.user.history, Quarantined, [64861e5916842610f75fe0db5aa937c9],
PUP.Optional.WebBar, C:\Users\chann\AppData\Local\WebBar\wb.user.settings, Quarantined, [64861e5916842610f75fe0db5aa937c9],
PUP.Optional.WebBar, C:\Windows\System32\config\systemprofile\AppData\Local\WebBar\wb.log, Quarantined, [d5150077faa078be81d6af0cf013ba46],
PUP.Optional.WinYahoo, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk, Quarantined, [0ae08ee91288979fb000b52be51eea16],
PUP.Optional.WebBar, C:\Windows\System32\Tasks\WBLaunchTask, Quarantined, [1bcf2651d2c8b28402519f5f39caaa56],
PUP.Optional.WebBar, C:\Windows\System32\Tasks\WBUpdateTask, Quarantined, [df0b0671cecc1e1871e2946a689bc040],
PUP.Optional.WinYahoo, C:\Windows\Tasks\Yahoo! Powered lodol.job, Quarantined, [c3270770bae0ad890416476dbe4639c7],
PUP.Optional.WinYahoo, C:\Windows\System32\Tasks\Yahoo! Powered lodol, Quarantined, [4b9fe0978218d75f809d239121e39c64],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\5.5.5995.17222\winwb.exe, Delete-on-Reboot, [5298fd7a1189ff375bb6a922a85a966a],
Adware.PremierOpinion, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion\PremierOpinion.lnk, Quarantined, [955595e26535bb7bfebb920cc14145bb],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\chrome.manifest, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\install.rdf, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\nscf.dat, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmcm.crx, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmcm.txt, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmls.dll, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmls64.dll, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmoci.bin, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmph.dll, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmropn.exe, Delete-on-Reboot, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmropn32.exe, Delete-on-Reboot, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmropn64.exe, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmservice.exe, Delete-on-Reboot, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\pmxf.dll, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\readme.txt, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\components\pmxg.dll, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\bootstrap.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\harness-options.json, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\install.rdf, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\locales.json, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\pmnx.dll, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\defaults\preferences\prefs.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\chrome.manifest, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\base64.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\self.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\timers.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\url.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\addon\runner.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console\plain-text.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\console\traceback.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\content-proxy.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\content-worker.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\loader.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\thumbnail.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\content\worker.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\heritage.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\namespace.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\core\promise.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\api-utils.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\cortex.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\errors.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\light-traits.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\list.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\memory.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\observer-service.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\window-utils.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\events\assembler.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\deprecated\traits\core.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\dom\events.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event\core.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\event\target.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\byte-streams.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\data.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\file.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\io\text-streams.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\core.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\html.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\loader.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\locale.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\l10n\prefs.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\lang\functional.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader\cuddlefish.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\loader\sandbox.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\net\url.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\page-mod\match-pattern.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\platform\xpcom.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\preferences\service.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\utils.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\private-browsing\window\utils.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\environment.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\events.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\globals.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\runtime.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\unload.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\system\xul-app.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\common.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\events.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\helpers.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\namespace.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\observer.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab-fennec.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab-firefox.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tab.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tabs-firefox.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\tabs.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\utils.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\tabs\worker.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\array.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\deprecate.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\list.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\object.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\registry.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\util\uuid.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\browser.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\namespace.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\window\utils.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\dom.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\fennec.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\firefox.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\loader.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\observer.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\tabs-fennec.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\sdk\windows\tabs-firefox.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\addon-sdk\lib\toolkit\loader.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\dpjs\data\content.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\dpjs\lib\dompilot.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\dpjs\lib\dputil.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.PremierOpinion, C:\Program Files\PremierOpinion\firefox\resources\dpjs\lib\main.js, Quarantined, [99514c2b9604f343f3ac3f7ba55dc739],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\unins000.dat, Quarantined, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\unins000.exe, Quarantined, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\5.5.5995.17222\Hardcodet.Wpf.TaskbarNotification.dll, Delete-on-Reboot, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\5.5.5995.17222\log4net.dll, Delete-on-Reboot, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\5.5.5995.17222\Newtonsoft.Json.dll, Delete-on-Reboot, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\5.5.5995.17222\System.Threading.dll, Delete-on-Reboot, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WebBar, C:\Program Files\WebBarMedia\5.5.5995.17222\winwb.exe.config, Quarantined, [15d52a4deab055e1c866c00828da10f0],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\HowToRemove.html, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\chromium-min.jpg, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\control panel-min-min.JPG, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\down.png, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\ff menu.JPG, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\ff search engine-min.png, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\hp-min ff.png, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\hp-min ie.png, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\search engine.gif, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\setup pages.gif, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\sp-min.png, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\start-min.jpg, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\HowToRemove\up.png, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\bapi_ff.dat, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\bapi_ie.dat, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\cede, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\install.log, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\lira, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\sama.dat, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\sase, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\Sqlite3.dll, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\tale.cfg, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\uninst.dat, Quarantined, [74760176c4d601355df6376619eb9868],
PUP.Optional.WinYahoo, C:\Users\chann\AppData\Local\{AF7E9922-8BD6-F59A-E64E-D072C2262CEA}\uninst.exe, Quarantined, [74760176c4d601355df6376619eb9868],
Physical Sectors: 0
(No malicious items detected)

(end)


Edited by Channeal, 25 October 2016 - 10:36 AM.

  • 0

Advertisements


#2
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 8,529 posts
Hi Channeal,

I am so sorry for the delayed reply. It looks as if Malwarebytes cleaned you up pretty good. There are a few things that need to be removed. Please do as follows:
  • Please copy the entire contents from start to end of the code box below into your notepad.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same directory as frst.exe (or frst64.exe) as fixlist.txt.

    start
    CreateRestorePoint:
    CloseProcesses:
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
    GroupPolicy: Restriction ? <======= ATTENTION
    GroupPolicyScripts: Restriction <======= ATTENTION
    GroupPolicyScripts\User: Restriction <======= ATTENTION
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
    SearchScopes: HKU\S-1-5-21-2764644833-1114247620-3834938357-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_16_39&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dgb%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutCtBtBtAyE0D0EtByD0Bzzzy0FtC0DyEtN0D0Tzu0StCyBtAtBtN1L2XzutAtFtByEtFtCyBtFyDyEtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StD0B0AyByCyEzztAtGtD0EtCyEtG0CyDyC0AtGtA0DzztDtGyDyCyEyDyEtBtB0D0CyByD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0CtA0Fzy0DyCtDtG0CyB0A0EtGyEtCtD0DtGzy0CyB0AtGyBtBtDtByD0E0AyDtBtD0Dzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDtC%26cr%3D1879745563%26a%3Dwbf_ir_16_39%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
    SearchScopes: HKU\S-1-5-21-2764644833-1114247620-3834938357-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_16_39&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dgb%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutCtBtBtAyE0D0EtByD0Bzzzy0FtC0DyEtN0D0Tzu0StCyBtAtBtN1L2XzutAtFtByEtFtCyBtFyDyEtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StD0B0AyByCyEzztAtGtD0EtCyEtG0CyDyC0AtGtA0DzztDtGyDyCyEyDyEtBtB0D0CyByD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0CtA0Fzy0DyCtDtG0CyB0A0EtGyEtCtD0DtGzy0CyB0AtGyBtBtDtByD0E0AyDtBtD0Dzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDtC%26cr%3D1879745563%26a%3Dwbf_ir_16_39%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
    U0 aswVmm; no ImagePath
    S3 cpuz140; \??\C:\Users\chann\AppData\Local\Temp\cpuz140\cpuz140_x32.sys [X]
    EmptyTemp:
    end
    
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you will find where you saved FRST. Please post it to your reply.
Next:

Please download Junkware Removal Tool.

Once you click the link above that takes you to the download, wait a couple seconds and the download box will appear. Click the Save File button in the box and save it to your desktop.
  • Disable your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Next:

Please download AdwCleaner by Xplode and save to your Desktop.

Once you click the link above that takes you to the download, wait a couple seconds and the download box will appear. Click the Save File button in the box and save it to your desktop.
  • Right-click on AdwCleaner.exe and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on the Scan button.
  • AdwCleaner will begin. Please be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
In your next reply, please post the following logs:
  • Fixlog.txt
  • JRT.txt
  • AdwCleaner[S#].txt

  • 0

#3
Channeal

Channeal

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 889 posts
Thanks very much for your response, DonnaB. 
 
I had pretty much decided to go ahead and reinstall Windows, but you seem to indicate that you do not consider that this is necessary. However, I just want to double check with you.....
 
You say that Malwarebytes had dealt well with the infection,  but if that is the case then I am not sure why the All-in-One Repair program I was advised to run (when Microsoft Edge started playing up) threw up so many problems. I do not know if you saw the log which I posted in my tech topic, but I think the errors were mostly concerning Windows file permissions. If these errors were caused by the virus (and I assume that they must have been, as the OS is newly installed and not a lot has been done on the Notebook since the installation) then they must have been present for the whole time since the virus and were not repaired by Malwarebytes.
 
 
Anyway.. .. .. .. .. I will carry out your instructions and get back to you with the results later.
 
Grateful thanks,
 
Chris

  • 0

#4
Channeal

Channeal

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 889 posts

2nd POST

 

Further to previous post, here are the logs: -

 

 

FIXLOG.TXT

 

Fix result of Farbar Recovery Scan Tool (x86) Version: 06-11-2016
Ran by chann (06-11-2016 16:09:57) Run:1
Running from C:\Users\chann\Desktop
Loaded Profiles: chann (Available Profiles: defaultuser0 & chann)
Boot Mode: Normal
==============================================
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
GroupPolicy: Restriction ? <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\S-1-5-21-2764644833-1114247620-3834938357-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_16_39&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dgb%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutCtBtBtAyE0D0EtByD0Bzzzy0FtC0DyEtN0D0Tzu0StCyBtAtBtN1L2XzutAtFtByEtFtCyBtFyDyEtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StD0B0AyByCyEzztAtGtD0EtCyEtG0CyDyC0AtGtA0DzztDtGyDyCyEyDyEtBtB0D0CyByD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0CtA0Fzy0DyCtDtG0CyB0A0EtGyEtCtD0DtGzy0CyB0AtGyBtBtDtByD0E0AyDtBtD0Dzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDtC%26cr%3D1879745563%26a%3Dwbf_ir_16_39%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2764644833-1114247620-3834938357-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://uk.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_16_39&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dgb%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutCtBtBtAyE0D0EtByD0Bzzzy0FtC0DyEtN0D0Tzu0StCyBtAtBtN1L2XzutAtFtByEtFtCyBtFyDyEtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2StD0B0AyByCyEzztAtGtD0EtCyEtG0CyDyC0AtGtA0DzztDtGyDyCyEyDyEtBtB0D0CyByD0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0CtA0Fzy0DyCtDtG0CyB0A0EtGyEtCtD0DtGzy0CyB0AtGyBtBtDtByD0E0AyDtBtD0Dzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDtC%26cr%3D1879745563%26a%3Dwbf_ir_16_39%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome&p={searchTerms}
U0 aswVmm; no ImagePath
S3 cpuz140; \??\C:\Users\chann\AppData\Local\Temp\cpuz140\cpuz140_x32.sys [X]
EmptyTemp:
end
*****************
Restore point was successfully created.
Processes closed successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
"C:\Windows\system32\GroupPolicy\Machine" => not found.
C:\Windows\system32\GroupPolicy\User => moved successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-2764644833-1114247620-3834938357-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully.
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
aswVmm => service removed successfully.
cpuz140 => service removed successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 32768 B
DOMStoree, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 22548850 B
Java, Flash, Steam htmlcache => 4053 B
Windows/system/drivers => 38081966 B
Edge => 65381651 B
Chrome => 92082451 B
Firefox => 66799782 B
Opera => 56648970 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
LocalService => 41164 B
NetworkService => -652 B
defaultuser0 => 587916 B
chann => 246406935 B
RecycleBin => 4769353 B
EmptyTemp: => 565.9 MB temporary data Removed.
================================

The system needed a reboot.
==== End of Fixlog 16:12:45 ====
 
 
 
 
 
 
JRT.TXT
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 10 Home x86
Ran by chann (Administrator) on 06/11/2016 at 16:24:20.88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

File System: 0
 

Registry: 0
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06/11/2016 at 16:27:02.94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

 

 

 

 

ADWCLEANER(CO).TXT

 

 

# AdwCleaner v6.030 - Logfile created 06/11/2016 at 16:33:39
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-11-05.1 [Server]
# Operating System : Windows 10 Home  (X86)
# Username : chann - NEAL2-SONYVAIO
# Running from : C:\Users\chann\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support
 
***** [ Services ] *****
 
***** [ Folders ] *****
[-] Folder deleted: C:\Users\chann\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence

***** [ Files ] *****
 
***** [ DLL ] *****
 
***** [ WMI ] *****
 
***** [ Shortcuts ] *****
 
***** [ Scheduled Tasks ] *****
 
***** [ Registry ] *****
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.Protector
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\reimageplus.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.reimageplus.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\azlyrics.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\metrolyrics.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.azlyrics.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.metrolyrics.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\azlyrics.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\metrolyrics.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.azlyrics.com
[-] Key deleted: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.metrolyrics.com

***** [ Web browsers ] *****
[-] [C:\Users\chann\AppData\Local\Chromium\User Data\Default\Web data] [Search Provider] Deleted: yahoo! powered
[-] [C:\Users\chann\AppData\Local\Chromium\User Data\Default] [startup_urls] Deleted: hxxps://uk.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_ir_16_39&param1=1&param2=f%3D7%26b%3Dchmm%26cc%3Dgb%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutCtBtBtAyE0D0EtByD0Bzzzy0FtC0DyEtN0D0Tzu0StCyBtAtBtN1L2XzutAtFtByEtFyCtFyDtBtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtA0Ezyzz0D0A0BtGtB0C0DyDtGyE0Czy0DtGyD0FtCyDtGtB0B0A0DtCyByCtA0DyEyCzz2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0F0CtA0Fzy0DyCtDtG0CyB0A0EtGyEtCtD0DtGzy0CyB0AtGyBtBtDtByD0E0AyDtBtD0Dzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDtB%26cr%3D1344378111%26a%3Dwbf_ir_16_39%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome
[-] [C:\Users\chann\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: uk.ask.com

*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [3896 Bytes] - [06/11/2016 16:33:39]
C:\AdwCleaner\AdwCleaner[S0].txt - [3645 Bytes] - [06/11/2016 16:32:39]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [4042 Bytes] ##########
 
 
Thanks again for your help.
 
Chris.

 


  • 0

#5
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 8,529 posts
Hi Channeal,

You're welcome! :) How is the computer behaving now?

Only time I would ever consider reinstalling Windows would be as a last resort. There are little unknown tricks that could be used to fix any problem like you found using the All In One repair tool, though most people don't know about these little tricks or don't know to even ask. I have no idea why AIO found so many problems that needed to be fixed on a new install. I might even try it on mine to see if it will fix a few things for me. Had my HHD drive replaced over the summer and the guy who did it for me reinstalled Windows 7. Ever since, the Windows sounds chime long after the desktop has loaded, so I know something isn't right and every thing I find about how to fix suggests a repair install.

Yes. Malwarebytes did a fine job removing whatever was left behind from that program that you inadvertently installed. That is so easy to do. They put those download button right next to the name of the software you intend to download so if you don't take a moment to actually read the page, you can easily click on thew wrong download button.

I am going to have you run another Malwarebytes scan and post the log so we can see if anything else is found. I doubt it, but doesn't hurt to check. Make sure the program is updated before you run the scan, please.

Donna :)
  • 0

#6
Channeal

Channeal

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 889 posts

Hello Donna,

 

Hope you are well.

 

The notebook seems to be running okay. The freaky thing about this infection though is that I thought that the scans I ran at the time had dealt with everything and I continued to enjoy my 'new' laptop with everything running well for quite some time. I had actually forgotten all about what had happened and it was only when I suddenly stopped being able to open Microsoft Edge - and subsequently ran the All-in-One repair program which told me that one of the problems was left over from a previous infection - that I remembered. Am just hoping that no more hidden problems suddenly come to the surface!

 

The only problem I have had  - and one which persisted after carrying out your fixes - is that a browser called 'Chromium' (not to be confused with 'Chrome') kept opening at the same time as Microsoft Edge the first time I went into it after starting up the notebook. It was not to be found in the list of Programs, so could not be uninstalled. If I did a search for it, Cortana told me it was a desktop app and let me click on the name to open it. Last night, I managed to find the file in which it was situated and just deleted it. It no longer comes up at the same time as Microsoft Edge and Cortana no longer finds it. Rather annoyingly though, it is still included as an option for a default web browser and I have no idea how to get rid of that: maybe I will just have to live with it! The strange thing is though, I do not think this problem existed until the problem with Microsoft Edge was rectified. ​I seem to specialise in unusual problems though! :)

 

Anyway, I ran the Malwarebytes scan as requested. The results are below, but it does not seems to have found any problems

 

Btw, sorry to hear that you have got possible problems with your computer even after having a new HDD installed; that's really annoying! I hope you manage to sort it out. Running the All-in-One repair program is probably worth at least a try, as it does seem to be a very good program.

 

The hard drive on this notebook is pretty old and Crystaldisk Info indicated that that it is showing signs of potential problems, so I was very tempted to replace it before installing Windows 10. Part of me still wishes that I had, as I am a bit reluctant to bring over too many files from our old desktop computer in case it does go. I really should try to get over that though, as it might well last much longer than expected! :)

 

Thanks once again for your help.

 

Chris.

 

 

Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 07/11/2016
Scan Time: 10:45
Logfile: Malwarebytes 07.11.2016.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.11.07.04
Rootkit Database: v2016.10.31.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 10
CPU: x86
File System: NTFS
User: chann
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 296459
Time Elapsed: 11 min, 42 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)

(end)

Edited by Channeal, 07 November 2016 - 11:42 AM.

  • 0

#7
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 8,529 posts
Hi Channeal,
 

a browser called 'Chromium' (not to be confused with 'Chrome') kept opening at the same time as Microsoft Edge

I managed to find the file in which it was situated and just deleted it.

Do you recall the file path that you followed to find it?

The only entries in the FRST log above are these:

2016-09-28 13:15 - 2016-09-28 13:15 - 00002338 _____ C:\Users\chann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium.lnk
2016-09-28 13:15 - 2016-09-28 13:15 - 00000000 ____D C:\Users\chann\AppData\Local\chromium



When did you installed Windows 10? There certainly are a lot of files dated for Sep. 29th. I am wondering if it was not included with the media used to install Windows 10.

Besides Crystaldisk, have you ran chkdsk /r from a command prompt? A failing Hard Drive can cause some really weird things to occur that may seem to be associated with file corruption, etc.

The Malwarebytes log shows no sign of infection, so I comfortable removing the tools used.

Download DelFix by Xplode and save it to your desktop.
  • Run the tool by right click on the 51a5ce45263de-delfix.png icon and Run as administrator option.
  • Make sure that these ones are checked:
    • Remove disinfection tools
    • Purge system restore
    • Reset system settings
  • Push Run.
  • The program will run for a few seconds and display a notepad report.
    Paste it for my review.

  • 0

#8
Channeal

Channeal

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 889 posts
Hello Donna,
 
I think the Chromium files which I deleted were located by right-clicking on the browser name on the task bar when it was open (or something similar!). However, the deleted files are still in the Recycle Bin which tells me that they came from C:\Users\chann\AppData\Local
 
I can confirm that Windows 10 was installed on either the 28th or 29th September (the malware infection occurred on the first day, I believe). Yes, the Chromium browser may well have been present since the OS was installed. I am not 100% sure that the problem with Chromium opening at the same time as Microsoft Edge was not present from the start, as I was so unfamilar with Windows 10 and I was not really sure what was opening! I think there was at least a short period though when this was not happening before Microsoft Edge did its disappearing act! :)
 
I was unsure whether I had run chkdsk on the notebook since installing Windows 10, so I ran it this evening. It seems that it did find some errors. (Just how many more errors can this little ol' computer conjure up, I ask myself!) Results as follows: -.
 
 
Checking file system on C: The type of the file system is NTFS. A disk check has been scheduled. Windows will now check the disk.
 
Stage 1: Examining basic file system structure ... 154880 file records processed. File verification completed. 7631 large file records processed. 0 bad file records processed.
 
Stage 2: Examining file name linkage ... 205014 index entries processed. Index verification completed. 0 unindexed files scanned. 0 unindexed files recovered to lost and found.
 
Stage 3: Examining security descriptors ... Cleaning up 6651 unused index entries from index $SII of file 0x9. Cleaning up 6651 unused index entries from index $SDH of file 0x9. Cleaning up 6651 unused security descriptors. CHKDSK is compacting the security descriptor stream Security descriptor verification completed. 25068 data files processed. CHKDSK is verifying Usn Journal... 40305648 USN bytes processed. Usn Journal verification completed.
 
Stage 4: Looking for bad clusters in user file data ... 154864 files processed. File data verification completed.
 
Stage 5: Looking for bad, free clusters ... 54301811 free clusters processed. Free space verification is complete. Correcting errors in the Volume Bitmap. Windows has made corrections to the file system. No further action is required. 243684351 KB total disk space. 26131324 KB in 99664 files. 76008 KB in 25071 indexes. 0 KB in bad sectors. 269771 KB in use by the system. 65536 KB occupied by the log file. 217207248 KB available on disk. 4096 bytes in each allocation unit. 60921087 total allocation units on disk. 54301812 allocation units available on disk. Internal Info: 00 5d 02 00 31 e7 01 00 04 c3 03 00 00 00 00 00 .]..1........... e9 00 00 00 42 00 00 00 00 00 00 00 00 00 00 00 ....B...........
 
Windows has finished checking your disk. Please wait while your computer restarts.
 
 
I ran Delfix as suggested. Results as follows: -
 
 
# DelFix v1.010 - Logfile created 08/11/2016 at 19:53:04
# Updated 26/04/2015 by Xplode
# Username : chann - NEAL2-SONYVAIO
# Operating System : Windows 10 Home  (32 bits)
~ Removing disinfection tools ...
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\RegBackup
Deleted : C:\Users\chann\Desktop\FRST-OlderVersion
Deleted : C:\Users\chann\Desktop\Addition.txt
Deleted : C:\Users\chann\Desktop\AdwCleaner.exe
Deleted : C:\Users\chann\Desktop\AdwCleaner[C0].txt
Deleted : C:\Users\chann\Desktop\Fixlog.txt
Deleted : C:\Users\chann\Desktop\FRST.exe
Deleted : C:\Users\chann\Desktop\FRST.txt
Deleted : C:\Users\chann\Desktop\JRT.exe
Deleted : C:\Users\chann\Desktop\JRT.txt
Deleted : C:\Users\chann\Downloads\JRT.exe
~ Cleaning system restore ...
Deleted : RP #6 [allinonerepair | 10/23/2016 17:13:09]
Deleted : RP #7 [Windows Update | 10/29/2016 13:38:13]
Deleted : RP #8 [Windows Update | 10/29/2016 13:39:02]
Deleted : RP #11 [JRT Pre-Junkware Removal | 11/06/2016 16:24:26]
Deleted : RP #15 [JRT Pre-Junkware Removal | 11/06/2016 17:10:13]
Deleted : RP #16 [Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 | 11/07/2016 11:06:20]
New restore point created !
~ Resetting system settings ... OK
########## - EOF - ##########
 
Thanks,
Chris.

Edited by Channeal, 08 November 2016 - 02:07 PM.

  • 0

#9
DonnaB

DonnaB

    Miss Congeniality

  • GeekU Moderator
  • 8,529 posts
Hi Channeal,

Sorry for the delay. I does seem that Chromium is associated some how with the installation dates of the 28th or 29th of September. Not knowing where you got your OS media from, I can't really say for sure. I have never seen 3rd party browser software included in installation media other than what Microsoft has to offer. I was thinking that maybe, since many browsers are based on the Chromium source code, the file might be associated with another browser that was installed after you had installed Windows 10, but you said that when you clicked to Open Microsoft Edge, that Chromium would open, so I a guessing that file is\was associated with Microsoft Edge.
 

Correcting errors in the Volume Bitmap. Windows has made corrections to the file system. No further action is required.

It appears that some errors were fixed and there are 0 KB in bad sectors, so I wouldn't worry too much.

Delfix has removed all the tools, files and folders from your system which is clean as a whistle! If you have any questions concerning security, feel free to ask, otherwise, I can turn you back over to Phillpower2 if you have any questions concerning the tech side of any other problems you are experiencing.
  • 0

#10
Channeal

Channeal

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 889 posts
Okay Donna, thank you very much indeed for your help.

Hopefully all will be well now and there are no more hidden problems waiting to surface at a later date! :)

Chris.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP