Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Broken IE / Win update

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Broken IE / Win update

Unread postby markuk86 » May 7th, 2016, 1:08 pm

Hey guys. Been meaning to get this looked at for a while and now i've finally got a bit of free time.

The problem is i sometimes get random popups usually while on youtube. Internet Explorer has been dying for a long time. The page will just crash. So i've been using Crome with no problems apart from popups.
I've scanned with malwarebyte / superantivirus / spybot / eset and it finds nothing. So im asking for help from the pros. Im pretty sure there is some rubbish on this system, its used by a few people and some are not too bright :p

Heres my logs:



Thanks in advance!
You do not have the required permissions to view the files attached to this post.
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am
Advertisement
Register to Remove

Re: Broken IE / Win update

Unread postby pgmigg » May 8th, 2016, 2:21 pm

Hello markuk86,

Welcome to the forum! :)

I am pgmigg and I'll be helping you with any malware problems.

Before we begin, please read and follow these important guidelines, so things will proceed smoothly.
  1. The instructions being given are for YOUR computer and system only!
    Using these instructions on a different computer can cause damage to that computer and possibly render it inoperable!
  2. You must have Administrator rights, permissions for this computer.
  3. DO NOT run any other fix or removal tools unless instructed to do so!
  4. DO NOT install any other software (or hardware) during the cleaning process until we are done as well as
    DO NOT Remove, or Scan with anything on your system unless I ask. This adds more items to be researched.
    Extra Additions and Removals of files make the analysis more difficult.
  5. Only post your problem at (1) one help site. Applying fixes from multiple help sites can cause problems.
  6. Print each set of instructions if possible - your Internet connection will not be available during some fix processes.
  7. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  8. Only reply to this thread, do not start another one. Please, continue responding, until I give you the "All Clean!" :cheers:
    Absence of symptoms does not mean that everything is clear.

I am currently reviewing your logs and will return, as soon as possible, with additional instructions. In the meantime...

Note: If you haven't done so already, please read this topic ALL USERS OF THIS FORUM MUST READ THIS FIRST where the conditions for receiving help here are explained.

Please read all instructions carefully before executing and perform the steps, in the order given.
lf you have any questions or problems executing these instructions, <<STOP>> do not proceed, post back with the question or problem.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start


Failure to post replies within 72 hours will result in this thread being closed
User avatar
pgmigg
Admin/Teacher
Admin/Teacher
 
Posts: 5457
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Broken IE / Win update

Unread postby pgmigg » May 8th, 2016, 2:43 pm

Hello markuk86,

P2P Advisory!
IMPORTANT: There are signs of one or more P2P (Peer to Peer) File Sharing Programs installed on your computer.
BitTorrent

As long as you have the P2P program(s) installed, per Forum Policy, I can offer you no further assistance.
If you choose NOT to remove the program(s), please indicate that in your next reply and this topic will be closed.

Otherwise, please perform the following steps:

Step 1.
Remove P2P Program
  1. Click on Start, then click the Start Search box on the Start Menu.
  2. Copy and paste the value below without into the open text entry box:
    (Do not include the words Code: Select all - instead of it please click the Select all button next to Code: to select the entire script.)
    Code: Select all
     appwiz.cpl 
    and press Enter - the Unistall or change a program list will be opened.
  3. Click each Entry, as follows, one by one, if it exists, choose Uninstall, and give permission to Continue:
    BitTorrent
  4. Click on the Change/Remove button to uninstall it.
  5. When the program have been uninstalled, please close Control Panel
  6. Reboot (restart) your computer.
By using any form of P2P networking to download files you can anticipate infestations of malware to occur. The P2P program itself may be safe but the files may not - use P2P at your own risk!
Keep in mind that this practice may be the source of your current malware infestation.
Reference... siting risk factors, using P2P programs: How to Prevent the Online Invasion of Spyware and Adware

Step 2.
Run CKScanner
  1. Please download CKScanner from here
  2. Important: - Save it to your Desktop.
  3. Double-click CKScanner.exe and click Search For Files.
  4. After a very short time, when the cursor hourglass disappears, click Save List To File.
  5. A message box will verify the file saved.
  6. Double-click the CKFiles.txt icon on your Desktop and copy/paste the contents in your next reply.

Step 3.
No Anti-virus Software Installed!
Looking over your log... there is NO evidence of anti-virus software installed.. This puts you at serious risk.
Anti-virus software will help detect, cleanse, and erase harmful virus files on a computer, Web server, or network.
Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection.
Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories.

To protect your computer from infection please download an anti-virus program from one these reliable vendors.

  1. avast! Free Antivirus - Excellent detection, the freeware version includes email scanning (free for personal use) .
  2. A good (pay for) Anti-virus program is ESET NOD32 Antivirus - 30 day free trial.

Installing a new AV product.
Do NOT uninstall any existing anti-virus product yet!
  1. Download the new Anti-virus product to your computer desktop.
  2. Save any work. Close all applications, especially your Internet connection.
  3. Uninstall any existing anti-virus product... Use the AV uninstall option if available.
  4. Reboot your computer, if not done during the uninstall.
  5. Install the new AV product, following installation instructions.
  6. Check for updates to the new AV product, if not done during install setup.
  7. Run a full scan of your computer.
It is strongly recommended that you run only one antivirus program at a time.
Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.


Then:
Please tell me about your problems with Windows Updates as you mentioned in the label of your topic but did not add any comments or details.

Please post each log separately to prevent it being cut off by the forum post size limiter.
Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections....

Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Your decision about P2P programs
  3. Contents of CKFiles.txt log file
  4. Answer to my question related to Windows Updates

Thanks,
pgmigg

Failure to post replies within 72 hours will result in this thread being closed
User avatar
pgmigg
Admin/Teacher
Admin/Teacher
 
Posts: 5457
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Broken IE / Win update

Unread postby markuk86 » May 8th, 2016, 3:30 pm

Hello pgmigg and thanks for helping me!

I have done what you have asked.

Here is the log file.

I hope everything has been done correct, if not please forgive me!

The problem with windows update..appears to of fixed itself.

I do apologize for this.

Is everything else looking ok with my computer?
You do not have the required permissions to view the files attached to this post.
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am

Re: Broken IE / Win update

Unread postby pgmigg » May 8th, 2016, 6:01 pm

Hello markuk86,

The problem with windows update..appears to of fixed itself.

I do apologize for this.
You don't need to apologize. I glad to hear that at least one problem was gone - anyway we will check everything.
Is everything else looking ok with my computer?
It is to early to say something. Actually we made the first step from many others. Let continue...

Please post your logs here into the body of your replays - not as attachments unless I will ask you do that.

A quick question before we start.
ProxyEnable: [.DEFAULT] => Proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:53914;https=127.0.0.1:53914
Are you aware of this proxy, did you set it yourself?

Step 1.
For safety reason (to have a good registry to restore if needed), I will ask you to create a System Restore Point (SRP) before most of my instructions sets...
Create a System Restore Point
  1. Right-click on Computer and select Properties.
  2. In the left pane under Tasks please click System protection.
    If UAC prompts for an administrator password or approval, type the password or give your "permission to continue".
  3. Select System Protection, then choose Create.
  4. In the System Restore dialog box, type a description for the restore point and then click Create again.
    A window will pop up with "The Restore Point was created successfully" confirmation message.
  5. Click OK, then close the System Restore dialog.

If you have successfully created a System Restore Point... we can proceed.
If you have NOT successfully created a System Restore Point... do not go any further!
Please post back so we can determine why it was unsuccessful.


Step 2.
Remove Programs
  1. Click on Start, then click the Start Search box on the Start Menu.
  2. Copy and paste the value below without into the open text entry box:
    (Do not include the words Code: Select all - instead of it please click the Select all button next to Code: to select the entire script.)
    Code: Select all
     appwiz.cpl 
    and press Enter - the Unistall or change a program list will be opened.
  3. Click each Entry, as follows, one by one, if it exists, choose Uninstall, and give permission to Continue:
    Spybot - Search & Destroy
  4. Click on the Change/Remove button to uninstall it.
  5. When the program have been uninstalled, please close Control Panel
  6. Reboot (restart) your computer.

Step 3.
AdwCleaner
Please download AdwCleaner by Xplode onto your desktop.
  1. Close all open programs and internet browsers.
  2. Right click on adwcleaner.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
  3. Click on Scan. When the scan finishes, you'll see a message on the product window: "Pending. Please uncheck elements you don't want to remove."
  4. Press the Clean button.
  5. A log file C:\AdwCleaner[Sn].txt will automatically open. ([Sn] n = number of run)
  6. Please post the content of the C:\AdwCleaner[Sn].txt log file in your next reply.

Step 4.
Junkware Removal Tool
  1. Please download Junkware Removal Tool and save JRT.exe to your Desktop.
  2. Shut down your protection software as shown in This topic now to avoid potential conflicts.
  3. Right click on JRT.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
  4. Please be patient as this can take a while to complete depending on your system's specifications.
  5. On completion, a log file JRT.txt is saved to your desktop and will automatically open.
  6. Please post the contents of JRT.txt into your next reply.

Step 5.
OTL - Download
Please download OTL.exe by Old Timer and save it to your Desktop.

OTL - Scan
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
  1. Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
  2. Under Output, ensure that Standard Output is selected.
  3. Check the boxes labeled:
    • Include 64 bit scans
    • Scan All Users
    • LOP check
    • Purity check
    • Extra Registry > Use SafeList
  4. Click on Run Scan at the top left hand corner.
  5. When done, two Notepad files will open.
    • OTL.txt <-- Will be opened, maximized
    • Extras.txt <-- Will be minimized on task bar.
  6. Please post the contents of both OTL.txt and Extras.txt files in your next reply.

Please post each log separately to prevent it being cut off by the forum post size limiter.
Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections....

Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Answer for my question about proxy.
  3. Contents of the AdwCleaner[Sn].txt log file
  4. Contents of the JRT.txt log file
  5. Contents of a OTL.txt log file
  6. Contents of a Extras.txt log file
  7. Do you see any changes in computer behavior?

Thanks,
pgmigg

Failure to post replies within 72 hours will result in this thread being closed
User avatar
pgmigg
Admin/Teacher
Admin/Teacher
 
Posts: 5457
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Broken IE / Win update

Unread postby markuk86 » May 8th, 2016, 8:50 pm

Hello.

Do you have any problems executing the instructions?
Nope

Answer for my question about proxy.
No idea what a proxy is, is it bad?

Do you see any changes in computer behavior?
Not at the moment.

# AdwCleaner v5.115 - Logfile created 09/05/2016 at 01:29:07
# Updated 01/05/2016 by Xplode
# Database : 2016-05-08.4 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (X64)
# Username : mark - MARK-PC
# Running from : C:\Users\mark\Downloads\adwcleaner_5.115.exe
# Option : Clean
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

[-] File Deleted : C:\Windows\Reimage.ini

***** [ DLLs ] *****


***** [ WMI ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine
[-] Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
[-] Key Deleted : HKCU\Software\AppDataLow\Software\adawarebp

***** [ Web browsers ] *****

[-] [C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : uk.ask.com

*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1622 bytes] - [09/05/2016 01:29:07]
C:\AdwCleaner\AdwCleaner[S1].txt - [896 bytes] - [07/05/2016 03:03:04]
C:\AdwCleaner\AdwCleaner[S2].txt - [1791 bytes] - [09/05/2016 01:27:50]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1840 bytes] ##########

-------------------------

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.6 (04.25.2016)
Operating System: Windows 7 Home Premium x64
Ran by mark (Administrator) on 09/05/2016 at 1:32:44.35
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

File System: 17

Successfully deleted: C:\ProgramData\mntemp (File)
Successfully deleted: C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3ATYVQFS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5UM8H1E7 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CD9FRKP7 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWKRX4C6 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3ATYVQFS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5UM8H1E7 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CD9FRKP7 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CWKRX4C6 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)

Registry: 0

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09/05/2016 at 1:34:19.22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


OTL logfile created on: 5/9/2016 1:38:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\mark\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18282)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

15.96 Gb Total Physical Memory | 14.09 Gb Available Physical Memory | 88.27% Memory free
31.92 Gb Paging File | 30.00 Gb Available in Paging File | 93.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111.79 Gb Total Space | 18.43 Gb Free Space | 16.49% Space Free | Partition Type: NTFS
Drive E: | 931.41 Gb Total Space | 562.52 Gb Free Space | 60.39% Space Free | Partition Type: NTFS
Drive F: | 223.57 Gb Total Space | 223.44 Gb Free Space | 99.94% Space Free | Partition Type: NTFS

Computer Name: MARK-PC | User Name: mark | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2016/05/09 01:35:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\mark\Desktop\OTL.exe
PRC - [2016/05/08 20:24:32 | 007,391,632 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2016/05/08 20:24:31 | 000,243,296 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2016/04/08 03:53:54 | 000,065,176 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
PRC - [2016/03/08 11:07:02 | 002,789,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2016/03/08 11:07:02 | 001,880,960 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2016/03/08 07:15:05 | 000,424,384 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2015/12/14 00:48:02 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2015/11/05 19:19:26 | 000,457,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\aunhelper\aunhelper.exe
PRC - [2015/11/05 19:19:26 | 000,064,592 | ---- | M] () -- C:\Program Files (x86)\Common Files\aunhelper\worker.exe
PRC - [2015/11/05 01:12:06 | 000,188,072 | ---- | M] () -- C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
PRC - [2015/03/22 23:13:42 | 000,076,152 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/08/13 09:44:22 | 000,105,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2011/12/16 20:30:40 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011/12/16 20:30:38 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2011/12/16 19:02:56 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe


========== Modules (No Company Name) ==========

MOD - [2016/05/08 20:24:32 | 040,539,648 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2016/05/08 20:24:32 | 000,123,344 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\log.dll
MOD - [2016/05/08 20:24:31 | 000,135,816 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
MOD - [2016/03/08 11:07:02 | 000,020,352 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll


========== Services (SafeList) ==========

SRV:64bit: - [2016/05/08 20:24:31 | 000,243,296 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2016/03/31 01:17:56 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2016/03/08 11:07:02 | 006,474,112 | ---- | M] (NVIDIA Corporation) [On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe -- (NvStreamNetworkSvc)
SRV:64bit: - [2016/03/08 11:07:02 | 002,609,024 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe -- (NvStreamSvc)
SRV:64bit: - [2016/03/08 11:07:02 | 001,164,672 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV:64bit: - [2013/05/27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2011/12/09 00:38:24 | 000,607,456 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV:64bit: - [2010/04/07 00:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\AppleChargerSrv.exe -- (AppleChargerSrv)
SRV - [2016/04/30 01:10:40 | 000,835,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2016/04/19 21:33:06 | 001,362,464 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe -- (BEService)
SRV - [2016/04/08 15:28:05 | 000,269,504 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2016/04/08 03:53:54 | 000,065,176 | ---- | M] (Razer Inc.) [Auto | Running] -- C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe -- (Razer Chroma SDK Service)
SRV - [2016/04/02 18:07:33 | 002,119,688 | ---- | M] (Electronic Arts) [On_Demand | Stopped] -- E:\Origin\OriginClientService.exe -- (Origin Client Service)
SRV - [2016/03/08 11:07:02 | 001,880,960 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2016/03/08 07:15:05 | 000,424,384 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2015/12/14 00:48:02 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2015/11/05 19:19:26 | 000,457,808 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\aunhelper\aunhelper.exe -- (aunhelper)
SRV - [2015/11/05 01:12:06 | 000,188,072 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe -- (Razer Game Scanner Service)
SRV - [2015/03/22 23:13:42 | 000,076,152 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014/03/20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/08/13 09:44:22 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/07/13 16:27:00 | 000,769,432 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011/12/16 20:30:40 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/12/16 20:30:38 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011/12/16 19:02:56 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2016/05/08 20:25:07 | 000,037,144 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswKbd.sys -- (aswKbd)
DRV:64bit: - [2016/05/08 20:24:33 | 000,465,792 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2016/05/08 20:24:33 | 000,287,528 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswVmm.sys -- (aswVmm)
DRV:64bit: - [2016/05/08 20:24:33 | 000,166,432 | ---- | M] (AVAST Software) [Kernel | Auto | Stopped] -- C:\Windows\SysNative\drivers\aswStm.sys -- (aswStm)
DRV:64bit: - [2016/05/08 20:24:33 | 000,107,792 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2016/05/08 20:24:33 | 000,103,064 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr2.sys -- (aswRdr)
DRV:64bit: - [2016/05/08 20:24:33 | 000,074,544 | ---- | M] (AVAST Software) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\aswRvrt.sys -- (aswRvrt)
DRV:64bit: - [2016/05/08 20:24:33 | 000,037,656 | ---- | M] (AVAST Software) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\aswHwid.sys -- (aswHwid)
DRV:64bit: - [2016/05/08 20:24:31 | 001,070,904 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2016/04/07 12:56:10 | 000,203,800 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzudd.sys -- (rzudd)
DRV:64bit: - [2016/04/07 12:55:54 | 000,047,640 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzmpos.sys -- (rzmpos)
DRV:64bit: - [2016/04/07 12:55:50 | 000,051,224 | ---- | M] (Razer Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rzendpt.sys -- (rzendpt)
DRV:64bit: - [2016/03/08 11:07:02 | 000,205,456 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2016/03/08 11:07:02 | 000,047,760 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:64bit: - [2016/03/08 11:07:02 | 000,028,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:64bit: - [2016/01/16 19:59:24 | 000,022,704 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\EsgScanner.sys -- (EsgScanner)
DRV:64bit: - [2015/12/14 23:24:25 | 000,130,880 | ---- | M] (Razer, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rzpnk.sys -- (rzpnk)
DRV:64bit: - [2015/09/22 23:36:40 | 000,037,184 | ---- | M] (Razer, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rzpmgrk.sys -- (rzpmgrk)
DRV:64bit: - [2015/09/11 20:54:13 | 000,030,264 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dtultrascsibus.sys -- (dtultrascsibus)
DRV:64bit: - [2015/09/09 14:17:36 | 000,047,160 | ---- | M] (Disc Soft Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dtultrausbbus.sys -- (dtultrausbbus)
DRV:64bit: - [2015/06/17 18:04:24 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2014/04/18 16:02:50 | 000,129,472 | ---- | M] (Razer, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RzDxgk.sys -- (RzDxgk)
DRV:64bit: - [2013/08/22 13:40:24 | 000,040,664 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2013/08/14 16:50:21 | 000,045,856 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2012/10/03 16:14:56 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/01/27 10:39:33 | 000,787,736 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3xhc.sys -- (iusb3xhc)
DRV:64bit: - [2012/01/27 10:39:33 | 000,356,120 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iusb3hub.sys -- (iusb3hub)
DRV:64bit: - [2012/01/27 10:39:33 | 000,016,152 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iusb3hcs.sys -- (iusb3hcs)
DRV:64bit: - [2012/01/20 05:39:16 | 000,205,312 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ViaHub3.sys -- (VUSB3HUB)
DRV:64bit: - [2012/01/20 05:39:04 | 000,254,464 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xhcdrv.sys -- (xhcdrv)
DRV:64bit: - [2011/11/10 09:04:14 | 000,060,184 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2011/11/02 18:48:26 | 000,021,616 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\AppleCharger.sys -- (AppleCharger)
DRV:64bit: - [2011/08/11 07:54:16 | 000,104,560 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2011/08/09 06:42:36 | 000,315,696 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mvs91xx.sys -- (mvs91xx)
DRV:64bit: - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 04:23:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/21 04:23:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 01:01:09 | 000,679,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xnacc.sys -- (xnacc)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:53914;https=127.0.0.1:53914

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <-loopback>
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:53914;https=127.0.0.1:53914

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/en-gb/?pc=UE07&ocid=UE07DHP
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F9 25 48 62 80 A9 D1 01 [binary data]
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = EB 17 E6 80 7B A9 D1 01 [binary data]
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.91.2: C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.91.2: C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Users\mark\AppData\Roaming\raidcall\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@raidcall.kr/RCplugin: C:\Users\mark\AppData\Roaming\RCKR\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: E:\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF [2016/05/08 20:24:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com: C:\Program Files\AVAST Software\Avast\WebRep\FF [2016/05/08 20:24:33 | 000,000,000 | ---D | M]

[2013/06/08 20:21:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\mark\AppData\Roaming\Mozilla\Extensions
[2012/11/13 19:19:48 | 000,000,000 | ---D | M] (No name found) -- C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions
[2012/11/13 19:19:48 | 000,000,000 | ---D | M] (BitTorrentControl_v12) -- C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}

========== Chrome ==========

CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\
CHR - Extension: No name found = C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\
CHR - Extension: No name found = C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\
CHR - Extension: No name found = C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\
CHR - Extension: No name found = C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.60_0\
CHR - Extension: No name found = C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.1_0\
CHR - Extension: No name found = C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_1\
CHR - Extension: No name found = C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_1\

O1 HOSTS File: ([2013/08/17 00:01:04 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [VIAxHCUtl] C:\VIA_XHCI\usb3Monitor.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Razer Synapse] C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.)
O4 - HKU\S-1-5-21-3640800009-1063320712-4824981-1002..\Run: [CCleaner Monitoring] E:\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-3640800009-1063320712-4824981-1002..\Run: [Steam] E:\Steam\steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73} https://www.icloud.com/system/iCloud.cab (iCloud Web App Plugin)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://www.pcpitstop.com/nirvana/controls/pcmatic.cab (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4BDDE909-497E-466E-94E5-59D0D335FCC0}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - c:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2016/01/16 19:59:47 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2016/05/09 01:35:31 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\mark\Desktop\OTL.exe
[2016/05/09 01:31:23 | 001,610,816 | ---- | C] (Malwarebytes) -- C:\Users\mark\Desktop\JRT.exe
[2016/05/08 20:25:07 | 000,037,144 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys
[2016/05/08 20:24:41 | 000,000,000 | ---D | C] -- C:\Users\mark\AppData\Roaming\AVAST Software
[2016/05/08 20:24:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
[2016/05/08 20:24:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AV
[2016/05/08 20:24:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\AV
[2016/05/08 20:24:34 | 001,070,904 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2016/05/08 20:24:34 | 000,465,792 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2016/05/08 20:24:34 | 000,287,528 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswVmm.sys
[2016/05/08 20:24:34 | 000,166,432 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2016/05/08 20:24:34 | 000,107,792 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2016/05/08 20:24:34 | 000,103,064 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2016/05/08 20:24:34 | 000,074,544 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2016/05/08 20:24:34 | 000,037,656 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHwid.sys
[2016/05/08 20:24:33 | 000,398,152 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2016/05/08 20:24:32 | 000,052,184 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2016/05/08 20:24:17 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2016/05/08 20:24:09 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2016/05/07 10:36:06 | 000,000,000 | ---D | C] -- C:\FRST
[2016/05/07 10:30:14 | 002,379,264 | ---- | C] (Farbar) -- C:\Users\mark\Desktop\FRST64.exe
[2016/05/07 10:23:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2016/05/07 03:02:54 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2016/05/06 18:08:38 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2016/05/06 18:08:38 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2016/05/06 18:08:38 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2016/05/06 18:08:38 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2016/05/06 18:08:38 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MshtmlDac.dll
[2016/05/06 18:08:38 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
[2016/05/06 18:08:37 | 006,052,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2016/05/06 18:08:37 | 002,131,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2016/05/06 18:08:37 | 002,056,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2016/05/06 18:08:37 | 001,359,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmlmedia.dll
[2016/05/06 18:08:37 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmlmedia.dll
[2016/05/06 18:08:37 | 000,968,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2016/05/06 18:08:37 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2016/05/06 18:08:37 | 000,814,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2016/05/06 18:08:37 | 000,806,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2016/05/06 18:08:37 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2016/05/06 18:08:37 | 000,725,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2016/05/06 18:08:37 | 000,663,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2016/05/06 18:08:37 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2016/05/06 18:08:37 | 000,615,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2016/05/06 18:08:37 | 000,571,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2016/05/06 18:08:37 | 000,489,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2016/05/06 18:08:37 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2016/05/06 18:08:37 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2016/05/06 18:08:37 | 000,315,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2016/05/06 18:08:37 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2016/05/06 18:08:37 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2016/05/06 18:08:37 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2016/05/06 18:08:37 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2016/05/06 18:08:37 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2016/05/06 18:08:37 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2016/05/06 18:08:37 | 000,107,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2016/05/06 18:08:37 | 000,092,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2016/05/06 18:08:37 | 000,088,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MshtmlDac.dll
[2016/05/06 18:08:37 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll
[2016/05/06 18:08:37 | 000,076,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2016/05/06 18:08:37 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2016/05/06 18:08:37 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2016/05/06 18:08:37 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2016/05/06 18:08:37 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2016/05/06 18:08:37 | 000,034,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2016/05/06 18:08:37 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2016/05/06 18:08:37 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2016/05/06 17:22:51 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2016/05/06 17:22:51 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2016/05/06 17:22:51 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2016/05/06 17:22:51 | 000,535,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2016/05/06 17:22:50 | 000,176,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msorcl32.dll
[2016/05/06 17:22:50 | 000,159,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mtxoci.dll
[2016/05/06 17:22:50 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mtxoci.dll
[2016/05/06 17:17:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2016/05/06 17:09:27 | 000,381,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfds.dll
[2016/05/06 17:09:27 | 000,296,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfds.dll
[2016/05/06 17:00:51 | 000,275,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\InkEd.dll
[2016/05/06 17:00:51 | 000,216,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\InkEd.dll
[2016/05/06 17:00:51 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jnwmon.dll
[2016/05/06 17:00:51 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2016/05/06 17:00:51 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2016/05/06 17:00:50 | 005,551,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2016/05/06 17:00:50 | 003,998,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2016/05/06 17:00:50 | 003,943,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2016/05/06 17:00:50 | 002,084,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ole32.dll
[2016/05/06 17:00:50 | 001,732,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2016/05/06 17:00:50 | 001,464,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2016/05/06 17:00:50 | 001,212,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpcrt4.dll
[2016/05/06 17:00:50 | 000,880,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\advapi32.dll
[2016/05/06 17:00:50 | 000,706,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winload.efi
[2016/05/06 17:00:50 | 000,631,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winresume.efi
[2016/05/06 17:00:50 | 000,463,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certcli.dll
[2016/05/06 17:00:50 | 000,419,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2016/05/06 17:00:50 | 000,342,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certcli.dll
[2016/05/06 17:00:49 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2016/05/06 17:00:49 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adtschema.dll
[2016/05/06 17:00:49 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adtschema.dll
[2016/05/06 17:00:49 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2016/05/06 17:00:49 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2016/05/06 17:00:49 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2016/05/06 17:00:49 | 000,312,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2016/05/06 17:00:49 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rstrui.exe
[2016/05/06 17:00:49 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2016/05/06 17:00:49 | 000,215,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2016/05/06 17:00:49 | 000,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rpchttp.dll
[2016/05/06 17:00:49 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidpolicyconverter.exe
[2016/05/06 17:00:49 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msaudite.dll
[2016/05/06 17:00:49 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msaudite.dll
[2016/05/06 17:00:49 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rpchttp.dll
[2016/05/06 17:00:49 | 000,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2016/05/06 17:00:49 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2016/05/06 17:00:49 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\auditpol.exe
[2016/05/06 17:00:49 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\setbcdlocale.dll
[2016/05/06 17:00:49 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msobjs.dll
[2016/05/06 17:00:49 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msobjs.dll
[2016/05/06 17:00:49 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidapi.dll
[2016/05/06 17:00:49 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\appidapi.dll
[2016/05/06 17:00:49 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srclient.dll
[2016/05/06 17:00:49 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\auditpol.exe
[2016/05/06 17:00:49 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2016/05/06 17:00:49 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptbase.dll
[2016/05/06 17:00:49 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2016/05/06 17:00:49 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2016/05/06 17:00:49 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2016/05/06 17:00:49 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\appidcertstorecheck.exe
[2016/05/06 17:00:49 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2016/05/06 17:00:49 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2016/05/06 17:00:49 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2016/05/06 17:00:49 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2016/05/06 17:00:49 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2016/05/06 17:00:49 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\apisetschema.dll
[2016/05/06 17:00:49 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2016/05/06 17:00:49 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2016/05/06 17:00:49 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2016/05/06 17:00:49 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2016/05/06 17:00:49 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2016/05/06 17:00:49 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2016/05/06 17:00:49 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2016/05/06 17:00:49 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2016/05/06 17:00:49 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2016/05/06 17:00:48 | 003,169,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wucltux.dll
[2016/05/06 17:00:48 | 000,709,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapi.dll
[2016/05/06 17:00:48 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapi.dll
[2016/05/06 17:00:48 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuwebv.dll
[2016/05/06 17:00:48 | 000,174,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuwebv.dll
[2016/05/06 17:00:48 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuauclt.exe
[2016/05/06 17:00:48 | 000,098,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wudriver.dll
[2016/05/06 17:00:48 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wudriver.dll
[2016/05/06 17:00:48 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WinSetupUI.dll
[2016/05/06 17:00:48 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups2.dll
[2016/05/06 17:00:48 | 000,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wuapp.exe
[2016/05/06 17:00:48 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wups.dll
[2016/05/06 17:00:48 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wuapp.exe
[2016/05/06 17:00:48 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wups.dll
[2016/05/06 17:00:48 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wu.upgrade.ps.dll
[2016/05/06 17:00:47 | 000,760,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samsrv.dll
[2016/05/06 17:00:47 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\samlib.dll
[2016/05/06 17:00:46 | 000,862,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2016/05/06 17:00:46 | 000,372,736 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysNative\atmfd.dll
[2016/05/06 17:00:46 | 000,299,520 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2016/05/06 17:00:46 | 000,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\fontsub.dll
[2016/05/06 17:00:46 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[2016/05/06 17:00:46 | 000,046,080 | ---- | C] (Adobe Systems) -- C:\Windows\SysNative\atmlib.dll
[2016/05/06 17:00:46 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lpk.dll
[2016/05/06 17:00:46 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2016/05/06 17:00:46 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dciman32.dll
[2016/05/06 17:00:04 | 014,634,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmp.dll
[2016/05/06 17:00:04 | 012,625,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmploc.DLL
[2016/05/06 17:00:04 | 011,411,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wmp.dll
[2016/05/06 17:00:04 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\spwmp.dll
[2016/05/06 17:00:04 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\spwmp.dll
[2016/05/06 17:00:04 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdxm.ocx
[2016/05/06 17:00:04 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxmasf.dll
[2016/05/06 17:00:04 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msdxm.ocx
[2016/05/06 17:00:04 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxmasf.dll
[2016/05/06 17:00:03 | 012,625,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wmploc.DLL
[2016/05/02 13:41:13 | 000,000,000 | ---D | C] -- C:\Users\mark\AppData\Roaming\NVIDIA
[2016/04/25 11:27:26 | 001,400,792 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdevicedll.dll
[2016/04/11 09:14:30 | 000,516,056 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzaudiodll.dll
[2016/04/11 09:14:30 | 000,161,752 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rztouchdll.dll
[2016/04/11 09:14:30 | 000,123,352 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdisplaydll.dll
[2016/04/11 09:14:30 | 000,110,040 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzvirtualdev.dll
[2016/04/11 09:14:30 | 000,099,288 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\RzBTLE.dll
[2016/04/11 09:14:30 | 000,097,752 | ---- | C] (Razer Inc) -- C:\Windows\SysWow64\rzdevinfo.dll
[2013/08/15 12:04:59 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\mark\AppData\Roaming\pcouffin.sys
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2016/05/09 01:37:42 | 000,025,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016/05/09 01:37:42 | 000,025,664 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016/05/09 01:36:31 | 000,782,470 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2016/05/09 01:36:31 | 000,666,636 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2016/05/09 01:36:31 | 000,126,312 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2016/05/09 01:35:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\mark\Desktop\OTL.exe
[2016/05/09 01:31:25 | 001,610,816 | ---- | M] (Malwarebytes) -- C:\Users\mark\Desktop\JRT.exe
[2016/05/09 01:29:57 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/05/09 01:29:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016/05/09 01:28:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2016/05/09 01:08:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/05/08 20:39:39 | 000,479,536 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2016/05/08 20:25:16 | 000,001,037 | ---- | M] () -- C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
[2016/05/08 20:25:07 | 000,037,144 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys
[2016/05/08 20:24:40 | 000,001,922 | ---- | M] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2016/05/08 20:24:33 | 000,465,792 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2016/05/08 20:24:33 | 000,398,152 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2016/05/08 20:24:33 | 000,287,528 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswVmm.sys
[2016/05/08 20:24:33 | 000,166,432 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswStm.sys
[2016/05/08 20:24:33 | 000,107,792 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2016/05/08 20:24:33 | 000,103,064 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2016/05/08 20:24:33 | 000,074,544 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRvrt.sys
[2016/05/08 20:24:33 | 000,037,656 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswHwid.sys
[2016/05/08 20:24:32 | 000,052,184 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2016/05/08 20:24:31 | 001,070,904 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2016/05/08 20:21:37 | 000,468,480 | ---- | M] () -- C:\Users\mark\Desktop\CKScanner.exe
[2016/05/08 12:53:55 | 000,741,345 | ---- | M] () -- C:\Users\mark\Desktop\fail.png
[2016/05/07 10:30:16 | 002,379,264 | ---- | M] (Farbar) -- C:\Users\mark\Desktop\FRST64.exe
[2016/05/07 03:06:14 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_avchv_01009.Wdf
[2016/05/06 17:52:55 | 000,192,216 | ---- | M] (Malwarebytes) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2016/05/06 17:17:07 | 000,097,856 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2016/04/28 21:10:29 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2016/04/25 11:27:26 | 001,400,792 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdevicedll.dll
[2016/04/24 15:40:44 | 000,000,623 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2016/04/11 09:14:30 | 000,516,056 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzaudiodll.dll
[2016/04/11 09:14:30 | 000,161,752 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rztouchdll.dll
[2016/04/11 09:14:30 | 000,123,352 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdisplaydll.dll
[2016/04/11 09:14:30 | 000,110,040 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzvirtualdev.dll
[2016/04/11 09:14:30 | 000,099,288 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\RzBTLE.dll
[2016/04/11 09:14:30 | 000,097,752 | ---- | M] (Razer Inc) -- C:\Windows\SysWow64\rzdevinfo.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2016/05/08 20:25:16 | 000,001,037 | ---- | C] () -- C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
[2016/05/08 20:25:16 | 000,001,037 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
[2016/05/08 20:24:40 | 000,001,922 | ---- | C] () -- C:\Users\Public\Desktop\Avast Free Antivirus.lnk
[2016/05/08 20:21:35 | 000,468,480 | ---- | C] () -- C:\Users\mark\Desktop\CKScanner.exe
[2016/05/08 12:53:55 | 000,741,345 | ---- | C] () -- C:\Users\mark\Desktop\fail.png
[2016/05/07 03:06:14 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_avchv_01009.Wdf
[2016/03/22 12:56:52 | 037,609,528 | ---- | C] () -- C:\Windows\SysWow64\nvcompiler.dll
[2016/03/22 12:56:52 | 008,658,120 | ---- | C] () -- C:\Windows\SysWow64\nvptxJitCompiler.dll
[2016/03/22 12:56:52 | 000,571,912 | ---- | C] () -- C:\Windows\SysWow64\nvfatbinaryLoader.dll
[2016/03/06 21:47:10 | 000,000,166 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2016/03/03 09:47:18 | 001,589,248 | ---- | C] () -- C:\Windows\SysWow64\libmysql_d.dll
[2015/02/05 19:14:15 | 000,000,000 | ---- | C] () -- C:\Users\mark\AppData\Local\{D9B3F901-E567-43FF-92F5-F79303278988}
[2014/10/16 00:13:19 | 000,005,674 | ---- | C] () -- C:\Users\mark\AppData\Local\Temp6.html
[2014/10/16 00:13:17 | 000,001,955 | ---- | C] () -- C:\Users\mark\AppData\Local\Temp1.html
[2014/10/16 00:04:56 | 000,007,527 | ---- | C] () -- C:\Users\mark\AppData\Local\Temp12.html
[2014/05/07 21:46:19 | 000,007,602 | ---- | C] () -- C:\Users\mark\AppData\Local\Resmon.ResmonCfg
[2013/08/20 20:04:04 | 000,000,125 | -HS- | C] () -- C:\ProgramData\.zreglib
[2013/08/15 12:04:59 | 000,007,859 | ---- | C] () -- C:\Users\mark\AppData\Roaming\pcouffin.cat
[2013/08/15 12:04:59 | 000,001,167 | ---- | C] () -- C:\Users\mark\AppData\Roaming\pcouffin.inf
[2013/02/11 20:17:59 | 000,843,900 | ---- | C] () -- C:\Users\mark\AppData\Local\census.cache
[2013/02/11 20:17:54 | 000,093,980 | ---- | C] () -- C:\Users\mark\AppData\Local\ars.cache
[2013/02/11 20:14:23 | 000,000,036 | ---- | C] () -- C:\Users\mark\AppData\Local\housecall.guid.cache
[2012/10/22 20:10:41 | 000,007,750 | ---- | C] () -- C:\Users\mark\AppData\Local\Temp14.html
[2012/09/26 10:05:09 | 000,003,072 | ---- | C] () -- C:\Users\mark\AppData\Local\file__0.localstorage

========== ZeroAccess Check ==========

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2015/08/06 19:04:07 | 014,176,768 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2015/08/06 18:44:51 | 012,875,776 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 02:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 02:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/10/19 19:39:58 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2013/10/19 19:39:58 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2015/10/11 13:44:10 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\.minecraft
[2016/03/17 08:39:34 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\.mono
[2016/05/08 20:24:41 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\AVAST Software
[2016/02/17 22:39:11 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Battle.net
[2013/09/12 20:46:28 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2015/03/21 01:59:26 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\DAEMON Tools Ultra
[2016/04/08 19:40:51 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Decipher Media
[2016/03/06 21:47:10 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\EPM DayZ RCon Tool
[2015/04/04 01:42:58 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\ftblauncher
[2015/11/17 19:40:31 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\ifonebox
[2015/11/25 20:12:37 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\iFunbox_UserCache
[2014/10/13 17:51:13 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\JAM Software
[2015/03/31 00:38:05 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\java
[2014/04/05 19:11:53 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Kalypso Media
[2013/10/21 23:05:51 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\No Company Name
[2015/09/25 19:45:02 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\OBS
[2013/07/07 22:14:36 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Oracle
[2015/08/22 21:32:23 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Origin
[2012/09/25 16:10:12 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\raidcall
[2012/12/03 23:02:50 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\RCKR
[2014/01/27 21:42:26 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\rcru
[2016/04/06 15:07:42 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\redsn0w
[2015/10/30 22:04:21 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Riot Games
[2015/12/13 21:34:02 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Steam
[2015/11/16 00:14:01 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\TaiG
[2015/11/06 05:40:59 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Tenorshare
[2015/11/26 23:29:22 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Tenorshare iPhone Data Recovery
[2015/02/21 15:52:16 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\The Creative Assembly
[2015/11/14 17:32:19 | 000,000,000 | -H-D | M] -- C:\Users\mark\AppData\Roaming\tmp_backup
[2016/01/21 02:47:53 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Tropico 5
[2016/05/09 01:23:46 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\TS3Client
[2013/10/10 16:27:05 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\TuneUp Software
[2016/02/06 14:24:32 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Vibosoft
[2015/11/18 16:27:31 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\WindSolutions

========== Purity Check ==========



< End of report >
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am

Re: Broken IE / Win update

Unread postby markuk86 » May 8th, 2016, 8:54 pm

OTL Extras logfile created on: 5/9/2016 1:38:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\mark\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18282)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

15.96 Gb Total Physical Memory | 14.09 Gb Available Physical Memory | 88.27% Memory free
31.92 Gb Paging File | 30.00 Gb Available in Paging File | 93.99% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111.79 Gb Total Space | 18.43 Gb Free Space | 16.49% Space Free | Partition Type: NTFS
Drive E: | 931.41 Gb Total Space | 562.52 Gb Free Space | 60.39% Space Free | Partition Type: NTFS
Drive F: | 223.57 Gb Total Space | 223.44 Gb Free Space | 99.94% Space Free | Partition Type: NTFS

Computer Name: MARK-PC | User Name: mark | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "E:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "E:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "E:\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "E:\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{20543E9D-DFB6-4CD1-9B38-0DBFDA017595}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamnetworkservice.exe |
"{2CB1C1AD-56B3-4AE8-A0B6-648D0914D23A}" = lport=47995 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{4B6C9EB8-1109-46C3-9C45-60BCD94E7FDD}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe |
"{64EBCBEB-E493-4ABE-85F8-4A8EDB542A54}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |
"{735CE996-09A8-42AD-8703-7B7175155AEF}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamnetworkservice.exe |
"{ACDA0EFF-40ED-434F-9BA9-F65567C25E9A}" = lport=35043 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe |
"{AD055F2A-269E-4901-884F-9D839D68FC77}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{C308A221-EC37-4090-AC94-9BE69F7834D2}" = lport=80 | protocol=6 | dir=in | app=e:\assassin's creed syndicate\acs.exe |
"{D2264650-9E1F-40EC-9B56-8E915D99A7A2}" = lport=47998 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamuseragent.exe |
"{E68CB7C7-BF48-4B61-8B72-714A730E5667}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03816FAF-2B0F-48F8-84D5-D83A1202F857}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{09FC61A9-5930-4245-961E-FC54386FE78E}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\prison architect\prison architect.exe |
"{0E42A939-7E73-42C6-ADC6-C629C0126D0C}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\half-life\hl.exe |
"{110A3E1E-814C-4271-923C-F265A2D0C1CA}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\ark\shootergame\binaries\win64\shootergame.exe |
"{14499277-D0FD-4BF6-B947-549AC27BEFFE}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{16D9A462-E5E6-4485-8BE4-3E997363F136}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{22B4782F-3DAA-4857-96E2-F78CCF1399DC}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\xcom-enemy-unknown\binaries\win32\xcomgame.exe |
"{23F5FB2D-97D4-4C1C-9E97-FDA0D7C0B487}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{256E5409-639F-4FCD-A886-CA948BF9B482}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\prison architect\prison architect safe mode.exe |
"{25B4FCAD-FB24-4197-9810-807A73A75654}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{26FF2C9D-CB30-4935-8F17-1CF4D4239A1D}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\half-life\hl.exe |
"{34EB8187-8DB9-4F5D-8A46-DFF9250FDB46}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\arma 3\arma3launcher.exe |
"{4446FE25-169B-44FA-BFAD-20260D33FBD7}" = protocol=6 | dir=in | app=e:\steam\bin\steamwebhelper.exe |
"{4B4FADBC-298A-4278-B085-6A1578007FE2}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{4EA17FBE-C593-47BA-8B85-5DAC77854D83}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\rocketleague\binaries\win32\rocketleague.exe |
"{546E0973-121C-424F-A44B-D0BF83D6DD18}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{593CCC9E-41D5-4D57-9F28-15D11933DAD3}" = protocol=17 | dir=in | app=e:\nero\km\kwikmedia.exe |
"{5ACD8DB1-7F77-41AB-AD95-F4B8387C9DA6}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{5E74D050-B0B5-488E-8C38-78E274BF7AAE}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{6225B47C-E9CB-449F-9166-91EBBC93E67C}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\borderlandspresequel\binaries\win32\launcher.exe |
"{6379DC4C-3E24-4ACC-AA40-3FE4CF209333}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\prison architect\prison architect safe mode.exe |
"{63F87D35-9C77-4B4F-BC76-0BF723D4B6F8}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{69E7314F-25CD-4058-B67A-E378BD0BB09C}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{6B861669-025C-4D0D-ADC7-828E8D92DCC1}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\grand theft auto v\gtavlauncher.exe |
"{6C319226-F51E-4908-9F73-201433E1A085}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\arma 3\arma3.exe |
"{73032690-DF68-4651-8558-1D0130CB5521}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{78B60B80-4C10-4FCF-B256-A7ABCCACE186}" = protocol=17 | dir=in | app=e:\nero\nero blu-ray player\blu-rayplayer.exe |
"{7BC93ED0-D5D0-4E5D-A4B7-6A38BAADB106}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{7C13DAC1-0C65-4AC7-B1A4-EC064D54ABE8}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{7F042331-0343-4966-820C-ED3A8F3831AC}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\prison architect\prison architect.exe |
"{8561A5EA-92D8-4727-AF6F-C0A59825137A}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{8995D690-E797-4878-9CE0-064ED59CBCFC}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{92B32A09-9A52-46B8-8873-8843C4941973}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\age2hd\launcher.exe |
"{953E1D43-04A2-4186-8C62-D772CF3834B2}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\tom clancy's the division\thedivision.exe |
"{99337D6F-622B-4494-8434-3DCD47BA41E7}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{9BF12114-44EE-425F-AE70-413A796FB740}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{9D88426F-B773-4409-A519-AD827BC2D4D6}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{A31E11B1-455C-4FC6-A369-D2096F080DB0}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\arma 3\arma3launcher.exe |
"{A430C24D-FE60-4B1A-8CD3-5A2333E5EDA0}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{ACE658BC-D095-478D-B810-12E21067B98C}" = protocol=17 | dir=in | app=e:\battle.net\battle.net.exe |
"{AFAFF299-1F64-4683-A8CA-90BE54A73E45}" = protocol=6 | dir=in | app=e:\far cry primal\bin\fcprimal.exe |
"{B16297E3-68CB-41AA-ADC6-135B834497E0}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\ark\shootergame\binaries\win64\shootergame.exe |
"{B692BC2A-A182-48A3-B7CF-05A9DDC3B9E4}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\ark\shootergame\binaries\win64\shootergame_be.exe |
"{B9821E91-AF3E-4455-81CF-A3C517BB3721}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{BA43AF12-C3D6-4E96-80D9-50411EC76EB3}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\arma 3\arma3.exe |
"{BD0F4C30-4BD9-4519-B150-0F35CDF3342D}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\tom clancy's the division\thedivision.exe |
"{BD779D7B-2290-4C65-9DED-57643A66A7D4}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\rocketleague\binaries\win32\rocketleague.exe |
"{C10890CE-FB41-4AD3-B19F-A45E08E977C1}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\ark\shootergame\binaries\win64\shootergame_be.exe |
"{C2302F03-042B-4056-A19A-CAFC9416ECA9}" = protocol=6 | dir=in | app=e:\nero\km\kwikmedia.exe |
"{CB95E3D5-5497-436A-82A1-D19BA76E9467}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{CF124EA5-B6B0-4CD4-A35A-00762B34743B}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\borderlandspresequel\binaries\win32\launcher.exe |
"{CF503FD6-21C9-4C97-B39B-23BB78B185B0}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe |
"{DB835744-7DBC-4CA4-A10D-9EC8A0FEB84D}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\grand theft auto v\gtavlauncher.exe |
"{DBCA2201-8D86-4063-A23B-D68970C8A8A6}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2753\agent.exe |
"{DCB92140-3E60-481C-B781-B1F913771265}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\sid meier's civilization v\launcher.exe |
"{DCF1E09A-C55D-451B-8AE8-C5D4270B9B34}" = protocol=6 | dir=in | app=e:\nero\nero blu-ray player\blu-rayplayer.exe |
"{DD18B697-0131-4715-B374-31BDE72FA1A9}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\xcom-enemy-unknown\binaries\win32\xcomgame.exe |
"{DE300D4D-4A9A-41FD-A4F4-F49A9F9A71E3}" = protocol=17 | dir=in | app=e:\steam\steamapps\common\age2hd\launcher.exe |
"{DFCDBDED-1BBA-4873-AABC-D00456088D6E}" = protocol=17 | dir=in | app=e:\hearthstone\hearthstone.exe |
"{E546C21A-FAE1-4DC7-A6FD-B8E08B172B45}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.beta.2737\agent.exe |
"{E9E88D8E-2AC4-460C-9C47-0FE58633313E}" = protocol=6 | dir=in | app=e:\steam\steamapps\common\borderlands 2\binaries\win32\launcher.exe |
"{EFC57FF6-F3E8-41B6-A709-34CF7D98A25A}" = protocol=17 | dir=in | app=e:\steam\bin\steamwebhelper.exe |
"{F325AE63-BE07-4D63-A53F-0861D748D00C}" = protocol=6 | dir=in | app=e:\hearthstone\hearthstone.exe |
"{F5FF35F1-8F57-43E8-B4B4-4922B37598F1}" = protocol=6 | dir=in | app=e:\battle.net\battle.net.exe |
"TCP Query User{033105C2-377F-410C-BECC-6F779C71B581}E:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe" = protocol=6 | dir=in | app=e:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe |
"TCP Query User{1F93378D-2666-4A9D-98D6-6DD3E4B7A3E4}E:\bit\bittorrent.exe" = protocol=6 | dir=in | app=e:\bit\bittorrent.exe |
"TCP Query User{2E3740B9-40DE-4C59-88E4-EE4DA21365DC}E:\steam\steamapps\common\grand theft auto v\gta5.exe" = protocol=6 | dir=in | app=e:\steam\steamapps\common\grand theft auto v\gta5.exe |
"TCP Query User{32C8EEA8-8B1B-40FB-960F-5656324FC44D}E:\bit\bittorrent.exe" = protocol=6 | dir=in | app=e:\bit\bittorrent.exe |
"TCP Query User{68C51D8B-57DC-41B9-AF50-265986DB2C31}E:\hearthstone\hearthstone.exe" = protocol=6 | dir=in | app=e:\hearthstone\hearthstone.exe |
"TCP Query User{7A8C954D-7361-4BA8-B7F2-0AE9C448B22E}E:\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe" = protocol=6 | dir=in | app=e:\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe |
"TCP Query User{C5866978-F2B9-4549-A1E6-91B09C502263}E:\steam\steam.exe" = protocol=6 | dir=in | app=e:\steam\steam.exe |
"TCP Query User{E4507524-134C-412A-A1E4-D460A9D014D4}E:\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=6 | dir=in | app=e:\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"UDP Query User{3E92126E-41A1-4277-BC18-6E64EC2DEAD2}E:\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe" = protocol=17 | dir=in | app=e:\steam\steamapps\common\xcom-enemy-unknown\xew\binaries\win32\xcomew.exe |
"UDP Query User{76169D92-43F1-446F-BCFD-D9C0FDCF643E}E:\steam\steam.exe" = protocol=17 | dir=in | app=e:\steam\steam.exe |
"UDP Query User{9B2E0477-A884-4AFD-8CF9-B5A0F9BF5BBF}E:\bit\bittorrent.exe" = protocol=17 | dir=in | app=e:\bit\bittorrent.exe |
"UDP Query User{A63F0106-938C-4160-836C-5016E9805362}E:\steam\steamapps\common\grand theft auto v\gta5.exe" = protocol=17 | dir=in | app=e:\steam\steamapps\common\grand theft auto v\gta5.exe |
"UDP Query User{B78B2613-7C1F-4214-AB3F-0E46CF6CEDD9}E:\bit\bittorrent.exe" = protocol=17 | dir=in | app=e:\bit\bittorrent.exe |
"UDP Query User{B7C540CB-08A9-4DDE-B4D6-8FDD8F16BA54}E:\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe" = protocol=17 | dir=in | app=e:\steam\steamapps\common\borderlands 2\binaries\win32\borderlands2.exe |
"UDP Query User{DFAA7B89-FC94-4BAE-984A-8594B804DF1D}E:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe" = protocol=17 | dir=in | app=e:\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe |
"UDP Query User{E915D1E0-84C4-407A-B773-43BC818864C6}E:\hearthstone\hearthstone.exe" = protocol=17 | dir=in | app=e:\hearthstone\hearthstone.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0D3E9E15-DE7A-300B-96F1-B4AF12B96488}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23026
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{2937FD88-C9D6-4B82-B539-37CD0A572F42}" = Apple Application Support (64-bit)
"{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}" = Apple Mobile Device Support
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}" = Bonjour
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6199B534-A1B6-46ED-873B-97B0ECF8F81E}" = Intel® Trusted Connect Service Client
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1 RC
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A31C5565-90D9-4615-AE13-94D86C3836C7}" = iTunes
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 364.51
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 364.51
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 364.51
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.10.2.40
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 364.44
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.15.0428
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 2.10.2.40
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA GeForce Experience Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.34.4
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 2.10.2.40
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.34
"{BC958BD2-5DAC-3862-BB1A-C1BE0790438D}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23026
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{E70808B9-78FE-3081-9658-A3C9DBC9A798}" = Microsoft .NET Framework 4.5.1 RC
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.64.0
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.20
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"PremiumSoft Navicat Premium_is1" = PremiumSoft Navicat Premium 11.2
"Steam App 346110" = ARK: Survival Evolved
"Steam App 365590" = Tom Clancy's The Division
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"WhoCrashed_is1" = WhoCrashed 3.06

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{050d4fc8-5d48-4b8f-8972-47c82c46020f}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501
"{052A1E34-A54B-458C-A4E3-24C3E054754A}" = Nero Kwik Media
"{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}" = Razer Synapse
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{1B6F5E51-575E-4693-BCA2-7543570D076D}" = Nero Kwik Themes Basic
"{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}" = Minecraft
"{1F16820E-D0E7-4636-939E-45CBFEFB06E1}" = Nero Kwik Media Help (CHM)
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel(R) USB 3.0 eXtensible Host Controller Driver
"{2432E589-6256-4513-B0BF-EFA8E325D5F0}" = Nero SharedVideoCodecs
"{26A24AE4-039D-4CA4-87B4-2F83218091F0}" = Java 8 Update 91
"{29F67D84-3A70-456E-806A-52301B02070B}" = Nero Effects Basic
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{3AAB08A3-F129-4BD5-B409-AE674F93759D}" = Prerequisite installer
"{3DECD372-76A1-4483-BF10-B547790A3261}" = ON_OFF Charge B11.1102.1
"{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}" = Microsoft ASP.NET MVC 4 Runtime
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{56EC47AA-5813-4FF6-8E75-544026FBEA83}" = Apple Software Update
"{5B79E730-D897-4B8F-A1AD-7BB2D1F22B96}" = Nero Blu-ray Player Help (CHM)
"{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}" = Google Update Helper
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{6AFCA4E1-9B78-3640-8F72-A7BF33448200}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74d0e5db-b326-4dae-a6b2-445b9de1836e}" = Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83FCCFCD-46E3-43FB-A397-78BFD5A8980A}" = Nero Video
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A2563E55-3BEC-3828-8D67-E5E8B9E8B675}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.23026
"{A2FE691E-3F8E-4E30-AA7D-FF17AC77EA87}" = Nero Blu-ray Player
"{A7A0BF2E-31CC-49E3-9913-52C503EB969D}" = Nero Audio Pack 1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{ABC88553-8770-4B97-B43E-5A90647A5B63}" = Nero ControlCenter
"{AC76BA86-0804-1033-1959-001824166751}" = Adobe Refresh Manager
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.15)
"{ACE49D50-19CD-44A6-B192-46F985283B26}" = Nero PiP Effects Basic
"{B128179D-A5E1-43AC-9422-12A109ECD2A0}" = Nero Video Help (CHM)
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{BE960C1C-7BAD-3DE6-8B1A-2616FE532845}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.23026
"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components
"{C994C746-C6D0-4EBA-B09E-DF7B18381B69}" = Nero ControlCenter Help (CHM)
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{D7D28084-C2F5-48BA-916D-52A14E71D9F5}" = Nero Video 12
"{E17BCB76-9924-4BD5-B6D6-50D3407B4E74}" = Nero Disc Menus Basic
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{e46eca4f-393b-40df-9f49-076faf788d83}" = Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{f65db027-aff3-4070-886a-0d87064aabb1}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}" = Apple Application Support (32-bit)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Flash Player ActiveX" = Adobe Flash Player 21 ActiveX
"Adobe Flash Player NPAPI" = Adobe Flash Player 21 NPAPI
"Afterburner" = MSI Afterburner 3.0.0
"Avast" = Avast Free Antivirus
"Battle.net" = Battle.net
"CalloutsV" = Callouts V
"ESET Online Scanner" = ESET Online Scanner v3
"Google Chrome" = Google Chrome
"Hearthstone" = Hearthstone
"iFunbox_is1" = iFunbox (v3.0.3109.1352)
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"iPhone Data Recovery" = iPhone Data Recovery
"Magic ISO Maker v5.5 (build 0281)" = Magic ISO Maker v5.5 (build 0281)
"MagniDriver" = marvell 91xx driver
"Malwarebytes Anti-Malware_is1" = Malwarebytes Anti-Malware version 2.2.1.1043
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Open Broadcaster Software" = Open Broadcaster Software
"OpenAL" = OpenAL
"Origin" = Origin
"PremiumSoft Navicat Premium_is1" = PremiumSoft Navicat Premium 9.1
"QXNzYXNzaW5zQ3JlZWRJVkJsYWNrRmxhZw==_is1" = Assassins Creed IV Black Flag
"RaidCall" = RaidCall
"Razer Chroma SDK" = Razer Chroma SDK Core Components
"Razer Core" = Razer Core
"Rockstar Games Social Club" = Rockstar Games Social Club
"RTSS" = RivaTuner Statistics Server 6.1.1
"SafeZone 1.48.2066.101" = SafeZone Stable 1.48.2066.101
"SqliteBrowser3" = DB Browser for SQLite
"Steam App 107410" = Arma 3
"Steam App 200510" = XCOM: Enemy Unknown
"Steam App 221380" = Age of Empires II: HD Edition
"Steam App 233450" = Prison Architect
"Steam App 252950" = Rocket League
"Steam App 261640" = Borderlands: The Pre-Sequel
"Steam App 271590" = Grand Theft Auto V
"Steam App 49520" = Borderlands 2
"Steam App 8930" = Sid Meier's Civilization V
"Steam App 8980" = Borderlands
"TreeSize Free_is1" = TreeSize Free V3.2
"Tropico 5_is1" = Tropico 5
"Uplay" = Uplay
"Uplay Install 1875" = Assassin's Creed Syndicate
"Uplay Install 2010" = Far Cry Primal
"VLC media player" = VLC media player
"WinRAR archiver" = WinRAR 5.30 beta 5 (32-bit)
"World of Warcraft" = World of Warcraft

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/6/2016 10:14:28 PM | Computer Name = mark-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/6/2016 11:25:47 PM | Computer Name = mark-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

Error - 5/7/2016 2:51:29 AM | Computer Name = mark-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/7/2016 5:15:35 AM | Computer Name = mark-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/7/2016 5:20:39 AM | Computer Name = mark-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/7/2016 7:54:26 PM | Computer Name = mark-PC | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18163,
time stamp: 0x566c4c47 Faulting module name: ntdll.dll, version: 6.1.7601.19110,
time stamp: 0x5684255b Exception code: 0xc0000005 Fault offset: 0x00058c46 Faulting
process id: 0x168c Faulting application start time: 0x01d1a8bb95d794a9 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\SysWOW64\ntdll.dll Report Id: 0711a7d0-14af-11e6-87f5-902b3432cc24

Error - 5/8/2016 7:45:13 AM | Computer Name = mark-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/8/2016 3:20:51 PM | Computer Name = mark-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/8/2016 3:39:46 PM | Computer Name = mark-PC | Source = WinMgmt | ID = 10
Description =

Error - 5/8/2016 8:29:55 PM | Computer Name = mark-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 5/8/2016 8:29:06 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Live ID Sign-in Assistant service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
10000 milliseconds: Restart the service.

Error - 5/8/2016 8:29:06 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Streamer Network Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 5/8/2016 8:29:06 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Search service terminated unexpectedly. It has done this
1 time(s). The following corrective action will be taken in 30000 milliseconds:
Restart the service.

Error - 5/8/2016 8:29:06 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7031
Description = The Microsoft .NET Framework NGEN v4.0.30319_X86 service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 120000 milliseconds: Restart the service.

Error - 5/8/2016 8:29:06 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7031
Description = The Microsoft .NET Framework NGEN v4.0.30319_X64 service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 120000 milliseconds: Restart the service.

Error - 5/8/2016 8:29:07 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 5/8/2016 8:29:07 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Media Player Network Sharing Service service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 30000 milliseconds: Restart the service.

Error - 5/8/2016 8:29:07 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7034
Description = The Intel(R) Management and Security Application User Notification
Service service terminated unexpectedly. It has done this 1 time(s).

Error - 5/8/2016 8:29:07 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7031
Description = The Software Protection service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 120000 milliseconds:
Restart the service.

Error - 5/8/2016 8:32:50 PM | Computer Name = mark-PC | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).


< End of report >


Thanks again for the help, i hope i have done this correct!
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am

Re: Broken IE / Win update

Unread postby pgmigg » May 8th, 2016, 11:02 pm

Hello markuk86,

No idea what a proxy is, is it bad?
In computer networks, a proxy server is a server (a computer system or an application) that acts as an intermediary for requests from clients seeking resources from other servers. A client connects to the proxy server, requesting some service, such as a file, connection, web page, or other resource available from a different server and the proxy server evaluates the request as a way to simplify and control its complexity.
Today, most proxies are web proxies, facilitating access to content on the Internet and providing anonymity. The last two words may explain why some people try to use proxy setting for their browsers. It is not bad or good - it depends on who set it: the owner of computer or malware. Malware can alter your proxy settings. If altered, it can affect your ability to browse or download tools required for disinfection.

Step 1.
Check - Reset Proxy settings for Internet Explorer
  1. Please open Internet Explorer. Then click on Tools -> Internet Options -> Connections tab.
    Note: if your Internet Explore crashed during opening, the same result may be obtained via Start button, typing Control Panel in search box and pressing Enter, selecting Internet Options -> Connections tab.
  2. Click the LAN Settings... button and uncheck "Use a proxy server for your LAN"
    or change the settings to the proxy you normally use if you previously reconfigured it.
  3. Remove any unknown addresses from the Address box. 80 is the default Port so it does not have to be changed.
  4. Click OK... then click OK again.
  5. Close Internet Explorer and -restart- the computer.

Step 2.
TDSSKiller - Rootkit Removal Tool Image
Please download the TDSSKiller.exe by Kaspersky... save it to your Desktop. <-Important!!!
  1. Right-click on TDSSKiller.exe and select "Run As Administrator...".
    If TDSSKiller does not run... rename it. Right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. ektfhtw.com).
    If you don't see file extensions, please see: How to change the file extension.
  2. Click the Start Scan button. Do not use the computer during the scan!
  3. Click Change parameters
  4. Under Additional Options CHECK Verify file digital signatures
  5. IMPORTANT: Ensure Detect TDLFS file system remains UNCHECKED.
  6. Click OK if changes were made.
  7. Click Start scan and allow it to scan for Malicious objects.
    • If Malicious objects are detected, the default action will be Cure, ensure SKIP is selected... then click Continue
    • If suspicious objects are detected, the default action will be Skip, ensure Skip is selected... then click Continue
    • If Unsigned files are detected, the default action will be Skip, ensure Skip is selected... then click Continue
    DO NOT change the default actions, other than CURE to SKIP.
  8. You may be asked to reboot the computer to complete the process. Click on Reboot Now and allow the computer to reboot.
  9. A log will be created on your root drive (usually C:) drive. The log will have a name like Name.Version_Date_Time_log.txt.
    for example, C:\TDSSKiller.2.4.1.2_20.04.2010_15.31.43_log.txt.
  10. If no reboot is required, click on Report. A log file should appear.
  11. Please post the contents of the log file in your next reply

Step 3.
FRST - Run Fix Script
  1. Click Start
  2. Type notepad.exe in the search programs and files box and click Enter.
  3. A blank Notepad page should open.
    • Copy and Paste the following script into Notepad, Do not include the words Code: select all
    • (Click the select all button next to code to select the entire script).
    Code: Select all
    HKLM-x32\...\Run: [] => [X]
    AppInit_DLLs:  => No File
    ProxyEnable: [.DEFAULT] => Proxy is enabled.
    ProxyServer: [.DEFAULT] => http=127.0.0.1:53914;https=127.0.0.1:53914
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    SearchScopes: HKLM -> DefaultScope value is missing
    SearchScopes: HKLM-x32 -> DefaultScope value is missing
    S2 SBSDWSCService; F:\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
    S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]
    S3 ALSysIO; \??\C:\Users\ADMINI~1\AppData\Local\Temp\ALSysIO64.sys [X]
    FirewallRules: [TCP Query User{32C8EEA8-8B1B-40FB-960F-5656324FC44D}E:\bit\bittorrent.exe] => (Allow) E:\bit\bittorrent.exe
    FirewallRules: [UDP Query User{9B2E0477-A884-4AFD-8CF9-B5A0F9BF5BBF}E:\bit\bittorrent.exe] => (Allow) E:\bit\bittorrent.exe
    C:\ProgramData\BitRaider
    C:\Users\ADMINI~1\AppData\Local\Temp\ALSysIO64.sys
    Hosts:
    EmptyTemp:
    CMD: ipconfig /flushdns
    
  4. Save it next to FRST64.exe on your Desktop as filename fixlist.txt

    NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system!
  5. NOTE: It's important that both files, FRST64 and fixlist.txt are saved in the same location or the fix will not work.
  6. Right-click FRST64.exe and select "Run as administrator..." to run it.
  7. Press the Fix button just once. Then wait.
  8. When finished, it will create a Fixlog.txt log on your Desktop.
  9. Please post the content of the Fixlog.txt in your next reply.

Step 4.
OTL - Run Fix Script
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
  1. Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
  2. Underneath Output at the top, make sure Standard Output is selected.
  3. Highlight and copy the following entries: into the Image text box.
    (Do not include the words Code: Select all - instead of it please click the Select all button next to Code: to select the entire script.)
    Code: Select all
    :Commands
    [CREATERESTOREPOINT]
    
    :processes
    killallprocesses
    
    :OTL
    IE - HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
    [2012/11/13 19:19:48 | 000,000,000 | ---D | M] (BitTorrentControl_v12) -- C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
    O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://www.pcpitstop.com/nirvana/contro ... cmatic.cab (PCPitstop Exam)
    [2013/10/19 19:39:58 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
    [2013/10/19 19:39:58 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
    [2015/10/11 13:44:10 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\.minecraft
    [2016/03/17 08:39:34 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\.mono
    [2013/09/12 20:46:28 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
    [2015/03/21 01:59:26 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\DAEMON Tools Ultra
    [2016/04/08 19:40:51 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Decipher Media
    [2016/03/06 21:47:10 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\EPM DayZ RCon Tool
    [2015/04/04 01:42:58 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\ftblauncher
    [2015/11/17 19:40:31 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\ifonebox
    [2015/11/25 20:12:37 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\iFunbox_UserCache
    [2014/10/13 17:51:13 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\JAM Software
    [2014/04/05 19:11:53 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Kalypso Media
    [2013/10/21 23:05:51 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\No Company Name
    [2015/09/25 19:45:02 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\OBS
    [2015/08/22 21:32:23 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Origin
    [2012/09/25 16:10:12 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\raidcall
    [2012/12/03 23:02:50 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\RCKR
    [2014/01/27 21:42:26 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\rcru
    [2016/04/06 15:07:42 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\redsn0w
    [2015/11/16 00:14:01 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\TaiG
    [2015/02/21 15:52:16 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\The Creative Assembly
    [2015/11/14 17:32:19 | 000,000,000 | -H-D | M] -- C:\Users\mark\AppData\Roaming\tmp_backup
    [2016/05/09 01:23:46 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\TS3Client
    [2013/10/10 16:27:05 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\TuneUp Software
    [2016/02/06 14:24:32 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\Vibosoft
    [2015/11/18 16:27:31 | 000,000,000 | ---D | M] -- C:\Users\mark\AppData\Roaming\WindSolutions
    
    :Files
    C:\Windows\*.tmp
    C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
    C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
    C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
    C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    C:\ProgramData\.zreglib
    
    :commands
    [startexplorer]
    [emptytemp]
    
  4. Click under the Custom Scan/Fixes box and paste the copied text.
  5. Click the Run Fix button. If prompted... click OK.
  6. OTL may ask to reboot the machine. Please do so if asked.
  7. Let the program run unhindered and reboot the PC when it is done.
    When the computer reboots, and you start your usual account, a Notepad text file will appear.
  8. Copy the contents of that file and post it in your next reply. The log can also be found, based on the date/time it was created, as C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log
Please post each log separately to prevent it being cut off by the forum post size limiter.
Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections....

Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Contents of the TDSSKiller_version_dd.mm.yyyy_hh.mm.ss_log.txt log file
  3. Contents of the Fixlog.txt file
  4. Contents of the C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log log file after OTL FixScript run
  5. Do you see any changes in computer behavior?

Thanks,
pgmigg

Failure to post replies within 72 hours will result in this thread being closed
User avatar
pgmigg
Admin/Teacher
Admin/Teacher
 
Posts: 5457
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Broken IE / Win update

Unread postby markuk86 » May 9th, 2016, 8:00 am

Hi again.

Do you have any problems executing the instructions?
Step 4.
OTL - Run Fix Script

I did this but i got a message afterwards. Windows has discovered a change that will result in limited windows functionality.

The pc rebooted after and i had to enter my windows cd key again. Once i entered it all seems fine.

Fix result of Farbar Recovery Scan Tool (x64) Version:07-05-2016
Ran by mark (2016-05-09 12:45:48) Run:1
Running from C:\Users\mark\Desktop
Loaded Profiles: mark (Available Profiles: mark)
Boot Mode: Normal
==============================================

fixlist content:
*****************
HKLM-x32\...\Run: [] => [X]
AppInit_DLLs:  => No File
ProxyEnable: [.DEFAULT] => Proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:53914;https=127.0.0.1:53914
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
S2 SBSDWSCService; F:\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
S3 BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [X]
S3 ALSysIO; \??\C:\Users\ADMINI~1\AppData\Local\Temp\ALSysIO64.sys [X]
FirewallRules: [TCP Query User{32C8EEA8-8B1B-40FB-960F-5656324FC44D}E:\bit\bittorrent.exe] => (Allow) E:\bit\bittorrent.exe
FirewallRules: [UDP Query User{9B2E0477-A884-4AFD-8CF9-B5A0F9BF5BBF}E:\bit\bittorrent.exe] => (Allow) E:\bit\bittorrent.exe
C:\ProgramData\BitRaider
C:\Users\ADMINI~1\AppData\Local\Temp\ALSysIO64.sys
Hosts:
EmptyTemp:
CMD: ipconfig /flushdns
*****************

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
"" => Value data removed successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
SBSDWSCService => service not found.
BRDriver64_1_3_3_E02B25FC => service removed successfully
ALSysIO => service removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{32C8EEA8-8B1B-40FB-960F-5656324FC44D}E:\bit\bittorrent.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9B2E0477-A884-4AFD-8CF9-B5A0F9BF5BBF}E:\bit\bittorrent.exe => value removed successfully
"C:\ProgramData\BitRaider" => not found.
"C:\Users\ADMINI~1\AppData\Local\Temp\ALSysIO64.sys" => not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => 793.1 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 12:45:53 ====
You do not have the required permissions to view the files attached to this post.
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am

Re: Broken IE / Win update

Unread postby markuk86 » May 9th, 2016, 8:03 am

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== PROCESSES ==========
========== OTL ==========
HKU\S-1-5-21-3640800009-1063320712-4824981-1002\SOFTWARE\Microsoft\Internet Explorer\Main\\SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy| /E : value set successfully!
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\Plugins folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\modules folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\META-INF folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\lib folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\defaults\preferences folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\defaults folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\skin folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\sl folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\lib folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\core folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\WEATHER\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\WEATHER\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\WEATHER folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TWITTER\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TWITTER\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TWITTER\img folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TWITTER folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_POPUP\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_POPUP folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_EMBEDDED\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_EMBEDDED folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_BCAPI\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_BCAPI\autoTest\spec folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_BCAPI\autoTest\lib\jasmine-1.1.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_BCAPI\autoTest\lib folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_BCAPI\autoTest folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TESTER_BCAPI folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH_IN_NEW_TAB folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH\view\style\rsx folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH\view\style folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH\view\script folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH\view folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH\Css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH\buildSettings folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\SEARCH folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\RADIO_PLAYER\js\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\RADIO_PLAYER\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\RADIO_PLAYER\css\custom-theme folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\RADIO_PLAYER\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\RADIO_PLAYER folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\PRICE_GONG\menu_dlg folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\PRICE_GONG\images folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\PRICE_GONG\css\custom-theme folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\PRICE_GONG\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\PRICE_GONG\agreement folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\PRICE_GONG folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\Optimizer\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\Optimizer folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\NOTIFICATION\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\NOTIFICATION\images\light folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\NOTIFICATION\images\dark folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\NOTIFICATION\images folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\NOTIFICATION\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\NOTIFICATION folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\MULTI_RSS\js\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\MULTI_RSS\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\MULTI_RSS\img folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\MULTI_RSS\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\MULTI_RSS folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\HIGHLIGHTER\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\HIGHLIGHTER\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\HIGHLIGHTER folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\EMAIL_NOTIFIER\js\plugins folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\EMAIL_NOTIFIER\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\EMAIL_NOTIFIER\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\EMAIL_NOTIFIER folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\APPLICATION_BUTTON\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\APPLICATION_BUTTON\Js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\APPLICATION_BUTTON folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\404 folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\menu\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\menu\img folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\menu\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\menu folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\gf\img folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\gf\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\gf folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\gadgetFrame folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\dlg\ftd\images folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\dlg\ftd folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\dlg folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\searchProtector\searchProtectorSettingsDialog\images folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\searchProtector\searchProtectorSettingsDialog folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\searchProtector\SearchProtectorBubbleDialog\images folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\searchProtector\SearchProtectorBubbleDialog folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\searchProtector\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\searchProtector folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\options\js\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\options\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\options\images folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\options\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\options folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\myStuffDialogs folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\features\js\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\features\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\features folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\api folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ac\res folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ac\img folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ac\css folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ac folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\aboutBox\js folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\aboutBox\images folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\aboutBox folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826 folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome folder moved successfully.
C:\Users\mark\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} folder moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found.
Starting removal of ActiveX control {0E5F0222-96B9-11D3-8997-00104BD12D94}
C:\Windows\Downloaded Program Files\PCPitstop.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0E5F0222-96B9-11D3-8997-00104BD12D94}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E5F0222-96B9-11D3-8997-00104BD12D94}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{0E5F0222-96B9-11D3-8997-00104BD12D94}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0E5F0222-96B9-11D3-8997-00104BD12D94}\ not found.
Starting removal of ActiveX control {FFB3A759-98B1-446F-BDA9-909C6EB18CC7}
C:\Windows\Downloaded Program Files\PCMatic.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FFB3A759-98B1-446F-BDA9-909C6EB18CC7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB3A759-98B1-446F-BDA9-909C6EB18CC7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{FFB3A759-98B1-446F-BDA9-909C6EB18CC7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFB3A759-98B1-446F-BDA9-909C6EB18CC7}\ not found.
C:\Users\Default\AppData\Roaming\TuneUp Software\TU2012\Backups folder moved successfully.
C:\Users\Default\AppData\Roaming\TuneUp Software\TU2012 folder moved successfully.
C:\Users\Default\AppData\Roaming\TuneUp Software folder moved successfully.
Folder C:\Users\Default User\AppData\Roaming\TuneUp Software\ not found.
C:\Users\mark\AppData\Roaming\.minecraft\versions\1.9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\versions\1.8.8 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\versions\1.8.3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\versions\1.8 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\versions\1.7.9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\versions\1.7.4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\versions\1.7.10 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\versions\1.6.4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\versions folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\texturepacks-mp-cache folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\texturepacks folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\stats folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\server-resource-packs folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\screenshots folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New Worldf\stats folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New Worldf\region folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New Worldf\playerdata folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New Worldf\DIM1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New Worldf\DIM-1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New Worldf\data folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New Worldf folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New World\stats folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New World\region folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New World\playerdata folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New World\DIM1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New World\DIM-1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New World\data folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves\New World folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\saves folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\streaming folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\tile\piston folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\tile folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\step folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\random folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\portal folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\note folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\zombiepig folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\zombie folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\wolf folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\wither folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\spider folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\slime folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\skeleton folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\silverfish folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\sheep folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\pig folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\magmacube folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\irongolem folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\ghast folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\endermen folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\enderdragon folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\creeper folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\cow folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\chicken folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\cat folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\blaze folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob\bat folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\mob folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\minecart folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\liquid folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\fireworks folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\fire folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\dig folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\damage folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\ambient\weather folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\ambient\cave folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3\ambient folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound\step folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\sound folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\pe folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\tile\piston folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\tile folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\step folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\random folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\portal folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\note folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\zombiepig folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\zombie folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\wolf folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\silverfish folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\magmacube folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\irongolem folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\ghast folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\endermen folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\cat folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob\blaze folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\mob folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\liquid folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\fire folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\damage folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\ambient\weather folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\ambient\cave folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound\ambient folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newsound folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\newmusic folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources\music folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\resourcepacks folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\logs folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch-platform\6.5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch-platform\5.16 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch-platform\5.12 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch-platform folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch-external-platform\4.5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch-external-platform folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch\6.5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch\5.16 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch\5.12 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch\twitch folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv\twitch folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\tv folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\oshi-project\oshi-core\1.1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\oshi-project\oshi-core folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\oshi-project folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl_util\2.9.4-nightly-20150209 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl_util\2.9.1-nightly-20131120 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl_util\2.9.1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl_util\2.9.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl_util folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl-platform\2.9.4-nightly-20150209 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl-platform\2.9.1-nightly-20131120 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl-platform\2.9.1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl-platform\2.9.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl-platform folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl\2.9.4-nightly-20150209 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl\2.9.1-nightly-20131120 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl\2.9.1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl\2.9.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl\lwjgl folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl\lwjgl folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\lwjgl folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\bouncycastle\bcprov-jdk15on\1.47 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\bouncycastle\bcprov-jdk15on folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\bouncycastle folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\logging\log4j\log4j-core\2.0-beta9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\logging\log4j\log4j-core folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\logging\log4j\log4j-api\2.0-beta9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\logging\log4j\log4j-api folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\logging\log4j folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\logging folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\httpcomponents\httpcore\4.3.2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\httpcomponents\httpcore folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\httpcomponents\httpclient\4.3.3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\httpcomponents\httpclient folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\httpcomponents folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\commons\commons-lang3\3.3.2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\commons\commons-lang3\3.1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\commons\commons-lang3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\commons\commons-compress\1.8.1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\commons\commons-compress folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache\commons folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org\apache folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\org folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\sf\trove4j\trove4j\3.0.3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\sf\trove4j\trove4j folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\sf\trove4j folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\sf\jopt-simple\jopt-simple\4.6 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\sf\jopt-simple\jopt-simple\4.5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\sf\jopt-simple\jopt-simple folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\sf\jopt-simple folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\sf folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\jutils\jutils\1.0.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\jutils\jutils folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\jutils folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\jinput\jinput-platform\2.0.5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\jinput\jinput-platform folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\jinput\jinput\2.0.5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\jinput\jinput folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\jinput folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\dev\jna\platform\3.4.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\dev\jna\platform folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\dev\jna\jna\3.4.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\dev\jna\jna folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\dev\jna folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java\dev folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net\java folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\net folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\java3d\vecmath\1.5.2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\java3d\vecmath\1.3.1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\java3d\vecmath folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\java3d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\io\netty\netty-all\4.0.23.Final folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\io\netty\netty-all\4.0.15.Final folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\io\netty\netty-all\4.0.10.Final folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\io\netty\netty-all folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\io\netty folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\io folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-logging\commons-logging\1.1.3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-logging\commons-logging folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-logging folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-io\commons-io\2.4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-io\commons-io folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-io folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-codec\commons-codec\1.9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-codec\commons-codec folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\commons-codec folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\soundsystem\20120107 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\soundsystem folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\librarylwjglopenal\20100824 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\librarylwjglopenal folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\libraryjavasound\20101123 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\libraryjavasound folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\codecwav\20101023 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\codecwav folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\codecjorbis\20101023 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode\codecjorbis folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\paulscode folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\realms\1.8.3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\realms\1.7.39 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\realms\1.7.13 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\realms\1.6 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\realms\1.3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\realms folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\authlib\1.5.22 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\authlib\1.5.21 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\authlib\1.5.17 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\authlib\1.5.16 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\authlib\1.5.13 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\authlib\1.2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang\authlib folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\mojang folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\ibm\icu\icu4j-core-mojang\51.2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\ibm\icu\icu4j-core-mojang folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\ibm\icu folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\ibm folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\guava\guava\17.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\guava\guava\15.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\guava\guava\14.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\guava\guava folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\guava folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\code\gson\gson\2.2.4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\code\gson\gson\2.2.2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\code\gson\gson folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\code\gson folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google\code folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com\google folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\com folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\argo\argo\2.25_fixed folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\argo\argo folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries\argo folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\libraries folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\bin\natives folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\bin folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\skins\8a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\skins folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ff folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\fe folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\fd folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\fc folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\fb folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\fa folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f8 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f7 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f6 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\f0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ef folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ee folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ed folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ec folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\eb folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ea folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e8 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e7 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e6 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\e0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\df folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\de folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\dd folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\dc folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\db folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\da folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d8 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d7 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d6 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\d0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\cf folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ce folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\cd folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\cc folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\cb folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ca folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c8 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c7 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c6 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\c0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\bf folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\be folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\bd folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\bc folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\bb folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ba folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b8 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b7 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b6 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\b0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\af folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ae folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ad folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ac folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\ab folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\aa folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a9 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a8 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a7 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a6 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a5 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a4 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a3 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a2 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a1 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\a0 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\9f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\9e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\9d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\9c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\9b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\9a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\99 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\98 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\97 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\96 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\95 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\94 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\93 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\92 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\91 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\90 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\8f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\8e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\8d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\8c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\8b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\8a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\89 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\88 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\87 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\86 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\85 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\84 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\83 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\82 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\81 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\80 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\7f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\7e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\7d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\7c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\7b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\7a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\79 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\78 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\77 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\76 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\75 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\74 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\73 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\72 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\71 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\70 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\6f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\6e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\6d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\6c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\6b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\6a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\69 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\68 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\67 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\66 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\65 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\64 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\63 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\62 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\61 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\60 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\5f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\5e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\5d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\5c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\5b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\5a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\59 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\58 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\57 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\56 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\55 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\54 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\53 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\52 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\51 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\50 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\4f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\4e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\4d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\4c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\4b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\4a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\49 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\48 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\47 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\46 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\45 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\44 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\43 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\42 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\41 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\40 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\3f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\3e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\3d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\3c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\3b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\3a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\39 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\38 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\37 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\36 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\35 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\34 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\33 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\32 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\31 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\30 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\2f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\2e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\2d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\2c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\2b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\2a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\29 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\28 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\27 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\26 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\25 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\24 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\23 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\22 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\21 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\20 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\1f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\1e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\1d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\1c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\1b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\1a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\19 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\18 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\17 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\16 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\15 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\14 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\13 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\12 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\11 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\10 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\0f folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\0e folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\0d folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\0c folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\0b folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\0a folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\09 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\08 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\07 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\06 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\05 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\04 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\03 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\02 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\01 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects\00 folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\objects folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets\indexes folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft\assets folder moved successfully.
C:\Users\mark\AppData\Roaming\.minecraft folder moved successfully.
C:\Users\mark\AppData\Roaming\.mono\certs\Trust folder moved successfully.
C:\Users\mark\AppData\Roaming\.mono\certs\CA folder moved successfully.
C:\Users\mark\AppData\Roaming\.mono\certs folder moved successfully.
C:\Users\mark\AppData\Roaming\.mono folder moved successfully.
C:\Users\mark\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant\Local Store\#SharedObjects folder moved successfully.
C:\Users\mark\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant\Local Store folder moved successfully.
C:\Users\mark\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant\#airversion folder moved successfully.
C:\Users\mark\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant folder moved successfully.
C:\Users\mark\AppData\Roaming\DAEMON Tools Ultra\IconsCache folder moved successfully.
C:\Users\mark\AppData\Roaming\DAEMON Tools Ultra folder moved successfully.
C:\Users\mark\AppData\Roaming\Decipher Media\C57475953A7775874DA1EAEA4A62204D08E83920 folder moved successfully.
C:\Users\mark\AppData\Roaming\Decipher Media\C04F9A65D1B6F2F8861B5264B9DF501C02E83448 folder moved successfully.
C:\Users\mark\AppData\Roaming\Decipher Media\96AB506E51F08E8E938D64B2377552BE84FF7427 folder moved successfully.
C:\Users\mark\AppData\Roaming\Decipher Media\76DB59177B76E8B6E3F93AF268952D5598B37952 folder moved successfully.
C:\Users\mark\AppData\Roaming\Decipher Media\6832E3B028FBC11FF38343645471B46344A67C93 folder moved successfully.
C:\Users\mark\AppData\Roaming\Decipher Media\3055EE1E6E5AAA49739BED8A9ADEC657BDB1655A folder moved successfully.
C:\Users\mark\AppData\Roaming\Decipher Media folder moved successfully.
C:\Users\mark\AppData\Roaming\EPM DayZ RCon Tool\Downloads\EPMRCon\x86 folder moved successfully.
C:\Users\mark\AppData\Roaming\EPM DayZ RCon Tool\Downloads\EPMRCon\amd64 folder moved successfully.
C:\Users\mark\AppData\Roaming\EPM DayZ RCon Tool\Downloads\EPMRCon folder moved successfully.
C:\Users\mark\AppData\Roaming\EPM DayZ RCon Tool\Downloads folder moved successfully.
C:\Users\mark\AppData\Roaming\EPM DayZ RCon Tool folder moved successfully.
C:\Users\mark\AppData\Roaming\ftblauncher\launcher_styles folder moved successfully.
C:\Users\mark\AppData\Roaming\ftblauncher\authlib folder moved successfully.
C:\Users\mark\AppData\Roaming\ftblauncher folder moved successfully.
C:\Users\mark\AppData\Roaming\ifonebox folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\temp_files folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\FC folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\FB folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\F9 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\F7 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\F4 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\EF folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\EE folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\E7 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\E6 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\E3 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\E0 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\DE folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\DC folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\DA folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\D7 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\D5 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\D4 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\D3 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\D2 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\CF folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\CE folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\CD folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\CC folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\CB folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\C7 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\C5 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\C4 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\C2 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\C0 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\BB folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\B6 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\B5 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\B3 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\B2 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\B1 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\B0 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\AE folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\AB folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\A5 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\A4 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\A1 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\9F folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\9E folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\98 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\97 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\93 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\90 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\8D folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\8C folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\8B folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\8A folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\89 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\88 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\86 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\84 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\83 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\82 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\7D folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\7A folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\78 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\75 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\6B folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\6A folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\69 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\68 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\64 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\63 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\62 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\60 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\5F folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\5E folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\5D folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\5B folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\5A folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\56 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\55 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\54 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\52 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\51 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\50 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\4D folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\47 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\45 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\44 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\41 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\3F folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\3A folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\38 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\37 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\36 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\35 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\34 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\32 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\30 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\2D folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\2A folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\27 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\26 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\23 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\22 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\20 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\1E folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\1C folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\1B folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\19 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\18 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\13 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\11 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\10 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\0F folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\0E folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\0D folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\0A folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\07 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\02 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets\00 folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\ifb_assets folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache\app_downloads folder moved successfully.
C:\Users\mark\AppData\Roaming\iFunbox_UserCache folder moved successfully.
C:\Users\mark\AppData\Roaming\JAM Software\TreeSize Free folder moved successfully.
C:\Users\mark\AppData\Roaming\JAM Software folder moved successfully.
C:\Users\mark\AppData\Roaming\Kalypso Media\Launcher folder moved successfully.
C:\Users\mark\AppData\Roaming\Kalypso Media folder moved successfully.
C:\Users\mark\AppData\Roaming\No Company Name\No Client Name\No Client Internal Version folder moved successfully.
C:\Users\mark\AppData\Roaming\No Company Name\No Client Name folder moved successfully.
C:\Users\mark\AppData\Roaming\No Company Name folder moved successfully.
C:\Users\mark\AppData\Roaming\OBS\updates folder moved successfully.
C:\Users\mark\AppData\Roaming\OBS\shaderCache folder moved successfully.
C:\Users\mark\AppData\Roaming\OBS\services folder moved successfully.
C:\Users\mark\AppData\Roaming\OBS\sceneCollection folder moved successfully.
C:\Users\mark\AppData\Roaming\OBS\profiles folder moved successfully.
C:\Users\mark\AppData\Roaming\OBS\pluginData folder moved successfully.
C:\Users\mark\AppData\Roaming\OBS\logs folder moved successfully.
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am

Re: Broken IE / Win update

Unread postby markuk86 » May 9th, 2016, 8:04 am

C:\Users\mark\AppData\Roaming\OBS\crashDumps folder moved successfully.
C:\Users\mark\AppData\Roaming\OBS folder moved successfully.
C:\Users\mark\AppData\Roaming\Origin\Widget Updates folder moved successfully.
C:\Users\mark\AppData\Roaming\Origin\NucleusCache folder moved successfully.
C:\Users\mark\AppData\Roaming\Origin\CommonTitles folder moved successfully.
C:\Users\mark\AppData\Roaming\Origin\Cloud Saves folder moved successfully.
C:\Users\mark\AppData\Roaming\Origin\CatalogCache folder moved successfully.
C:\Users\mark\AppData\Roaming\Origin folder moved successfully.
C:\Users\mark\AppData\Roaming\raidcall\plugins folder moved successfully.
C:\Users\mark\AppData\Roaming\raidcall folder moved successfully.
C:\Users\mark\AppData\Roaming\RCKR\plugins folder moved successfully.
C:\Users\mark\AppData\Roaming\RCKR folder moved successfully.
C:\Users\mark\AppData\Roaming\rcru\plugins folder moved successfully.
C:\Users\mark\AppData\Roaming\rcru folder moved successfully.
C:\Users\mark\AppData\Roaming\redsn0w\shsh folder moved successfully.
C:\Users\mark\AppData\Roaming\redsn0w\resources folder moved successfully.
C:\Users\mark\AppData\Roaming\redsn0w folder moved successfully.
C:\Users\mark\AppData\Roaming\TaiG\ItunesDLL folder moved successfully.
C:\Users\mark\AppData\Roaming\TaiG\ipatch folder moved successfully.
C:\Users\mark\AppData\Roaming\TaiG folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\ui_cache folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\temp folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\scripts folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\save_games_multiplayer folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\save_games folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\resume folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\replays folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\logs folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\fx_cache folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\event_feed folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\custom_keys folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\camera bookmarks folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\battle_preferences folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila\advice_history folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly\Attila folder moved successfully.
C:\Users\mark\AppData\Roaming\The Creative Assembly folder moved successfully.
C:\Users\mark\AppData\Roaming\tmp_backup\c04f9a65d1b6f2f8861b5264b9df501c02e83448 folder moved successfully.
C:\Users\mark\AppData\Roaming\tmp_backup folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\logs folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\crashdumps folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\chats\ZlVYQ2NvMXp4V3NLcDZ3WGdXODhvKzhSa1lJPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\chats\RDVTSUdBNkUzZkw5QUpkdFg5WldDVU9IZVkwPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\chats\emZ1TDl4d21RdWpvSzZpZm5UakZwUU1rWXdrPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\chats\akg5WXhxR3U1Sm5zVXAxektyZ2gvQTZuajljPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\chats folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\ZlVYQ2NvMXp4V3NLcDZ3WGdXODhvKzhSa1lJPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\ZlVYQ2NvMXp4V3NLcDZ3WGdXODhvKzhSa1lJPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\ZlVYQ2NvMXp4V3NLcDZ3WGdXODhvKzhSa1lJPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\ZlVYQ2NvMXp4V3NLcDZ3WGdXODhvKzhSa1lJPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\ZG9YWHlVVytXeU55WmZkUWFhdUZMK1BjbTFnPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\ZG9YWHlVVytXeU55WmZkUWFhdUZMK1BjbTFnPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\ZG9YWHlVVytXeU55WmZkUWFhdUZMK1BjbTFnPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\S3l4dnMrSHdFQUhHVHNPTHR6cDBOcHpGNnFzPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\S3l4dnMrSHdFQUhHVHNPTHR6cDBOcHpGNnFzPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\S3l4dnMrSHdFQUhHVHNPTHR6cDBOcHpGNnFzPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\x3.cdn03.imgwykop.pl\c3201142 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\x3.cdn03.imgwykop.pl folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.titanfs.com\images\static_files folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.titanfs.com\images folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.titanfs.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.outlish.com\wp-content\uploads\images\stories\Dec2010\Dec6Issue35 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.outlish.com\wp-content\uploads\images\stories\Dec2010 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.outlish.com\wp-content\uploads\images\stories folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.outlish.com\wp-content\uploads\images folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.outlish.com\wp-content\uploads folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.outlish.com\wp-content folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.outlish.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.domain.tld folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.carbinegaming.com\zuploads folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.carbinegaming.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.bodhiavasa.net\wp-content\uploads\2015\03 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.bodhiavasa.net\wp-content\uploads\2015 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.bodhiavasa.net\wp-content\uploads folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.bodhiavasa.net\wp-content folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.bodhiavasa.net folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.altislife.co.uk\images folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\www.altislife.co.uk folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\thamtuhungthinh.com\wp-content\uploads\2014\05 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\thamtuhungthinh.com\wp-content\uploads\2014 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\thamtuhungthinh.com\wp-content\uploads folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\thamtuhungthinh.com\wp-content folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\thamtuhungthinh.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\static1.stopklatka.pl\library\F6\39\87453270.jpg\1.0 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\static1.stopklatka.pl\library\F6\39\87453270.jpg folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\static1.stopklatka.pl\library\F6\39 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\static1.stopklatka.pl\library\F6 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\static1.stopklatka.pl\library folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\static1.stopklatka.pl folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\s29.postimg.org\c7ho3orhj folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\s29.postimg.org folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\s27.postimg.org\3xelt38vn folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\s27.postimg.org folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\s21.postimg.org\kz47x9647 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\s21.postimg.org folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\s11.postimg.org\izp3f7qub folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\s11.postimg.org folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\modernhouseinsight.com\wp-content\uploads\2011\04 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\modernhouseinsight.com\wp-content\uploads\2011 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\modernhouseinsight.com\wp-content\uploads folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\modernhouseinsight.com\wp-content folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\modernhouseinsight.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\img2.wikia.nocookie.net\__cb20150124183223\gtawiki\images\d\d6 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\img2.wikia.nocookie.net\__cb20150124183223\gtawiki\images\d folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\img2.wikia.nocookie.net\__cb20150124183223\gtawiki\images folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\img2.wikia.nocookie.net\__cb20150124183223\gtawiki folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\img2.wikia.nocookie.net\__cb20150124183223 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\img2.wikia.nocookie.net folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\i60.tinypic.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\i59.tinypic.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\i.imgur.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\i.gyazo.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\grandtheftaltis.co.uk\forums\content\logo folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\grandtheftaltis.co.uk\forums\content folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\grandtheftaltis.co.uk\forums folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\grandtheftaltis.co.uk folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\fat.gfycat.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\cdn.meme.li\instances\500x folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\cdn.meme.li\instances folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\cdn.meme.li folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\cdn.homedit.com\wp-content\uploads\2012\10 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\cdn.homedit.com\wp-content\uploads\2012 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\cdn.homedit.com\wp-content\uploads folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\cdn.homedit.com\wp-content folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\cdn.homedit.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\blog.qualitybath.com\wp-content\uploads\2011\02 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\blog.qualitybath.com\wp-content\uploads\2011 folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\blog.qualitybath.com\wp-content\uploads folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\blog.qualitybath.com\wp-content folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\blog.qualitybath.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\battlefornarnia.com\community\public\style_images folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\battlefornarnia.com\community\public folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\battlefornarnia.com\community folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\battlefornarnia.com folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote\altislife.co.uk folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\remote folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\RDVTSUdBNkUzZkw5QUpkdFg5WldDVU9IZVkwPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\RDVTSUdBNkUzZkw5QUpkdFg5WldDVU9IZVkwPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\RDVTSUdBNkUzZkw5QUpkdFg5WldDVU9IZVkwPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\RDVTSUdBNkUzZkw5QUpkdFg5WldDVU9IZVkwPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\Q1l6akRuS29jeHF4NFFSaVIrWWx0MDVzMVFvPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\Q1l6akRuS29jeHF4NFFSaVIrWWx0MDVzMVFvPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\Q1l6akRuS29jeHF4NFFSaVIrWWx0MDVzMVFvPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\Q1l6akRuS29jeHF4NFFSaVIrWWx0MDVzMVFvPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\Ny9XMG9id2ZuOU44SWRyY003UWV1dFVQR0hNPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\Ny9XMG9id2ZuOU44SWRyY003UWV1dFVQR0hNPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\Ny9XMG9id2ZuOU44SWRyY003UWV1dFVQR0hNPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\Ny9XMG9id2ZuOU44SWRyY003UWV1dFVQR0hNPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\NXFKYzBnWWJxUTNEZERuUmhuNVhCRUtjU0hrPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\NXFKYzBnWWJxUTNEZERuUmhuNVhCRUtjU0hrPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\NXFKYzBnWWJxUTNEZERuUmhuNVhCRUtjU0hrPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\NXFKYzBnWWJxUTNEZERuUmhuNVhCRUtjU0hrPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\NVJzUSt1YWZBTjV1dHp3Q0dLOUR1YTRKMXlFPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\NVJzUSt1YWZBTjV1dHp3Q0dLOUR1YTRKMXlFPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\NVJzUSt1YWZBTjV1dHp3Q0dLOUR1YTRKMXlFPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\NVJzUSt1YWZBTjV1dHp3Q0dLOUR1YTRKMXlFPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\N2l0NWVNeEVkTGVSemlkblIraVV4dVFVY0U4PQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\N2l0NWVNeEVkTGVSemlkblIraVV4dVFVY0U4PQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\N2l0NWVNeEVkTGVSemlkblIraVV4dVFVY0U4PQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\N2l0NWVNeEVkTGVSemlkblIraVV4dVFVY0U4PQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\MWxOTmN6dEhvMTdwU3haaW5pVkY1T3Zja2YwPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\MWxOTmN6dEhvMTdwU3haaW5pVkY1T3Zja2YwPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\MWxOTmN6dEhvMTdwU3haaW5pVkY1T3Zja2YwPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\MWxOTmN6dEhvMTdwU3haaW5pVkY1T3Zja2YwPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\LzJhb2JMUENZWEdVV2U4aGRBcmtDM3Yrb1dNPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\LzJhb2JMUENZWEdVV2U4aGRBcmtDM3Yrb1dNPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\LzJhb2JMUENZWEdVV2U4aGRBcmtDM3Yrb1dNPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\K2tTVFB3S2dBNXNmZHNUZlBVMG5sZ1RGRmxzPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\K2tTVFB3S2dBNXNmZHNUZlBVMG5sZ1RGRmxzPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\K2tTVFB3S2dBNXNmZHNUZlBVMG5sZ1RGRmxzPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\K2tTVFB3S2dBNXNmZHNUZlBVMG5sZ1RGRmxzPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\emZ1TDl4d21RdWpvSzZpZm5UakZwUU1rWXdrPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\emZ1TDl4d21RdWpvSzZpZm5UakZwUU1rWXdrPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\emZ1TDl4d21RdWpvSzZpZm5UakZwUU1rWXdrPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\emZ1TDl4d21RdWpvSzZpZm5UakZwUU1rWXdrPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\dVI3bDVMSjIrUjI2Zm1qeFRXVWhIakdSMHFnPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\dVI3bDVMSjIrUjI2Zm1qeFRXVWhIakdSMHFnPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\dVI3bDVMSjIrUjI2Zm1qeFRXVWhIakdSMHFnPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\b1hQYUxoQTVvTVJZek1DdUdDdGRONmRvb2xjPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\b1hQYUxoQTVvTVJZek1DdUdDdGRONmRvb2xjPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\b1hQYUxoQTVvTVJZek1DdUdDdGRONmRvb2xjPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\b1hQYUxoQTVvTVJZek1DdUdDdGRONmRvb2xjPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\akhEUVE5ZUZqdW1GLzZzaWdLang4dG5YRzJzPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\akhEUVE5ZUZqdW1GLzZzaWdLang4dG5YRzJzPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\akhEUVE5ZUZqdW1GLzZzaWdLang4dG5YRzJzPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\akhEUVE5ZUZqdW1GLzZzaWdLang4dG5YRzJzPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\akg5WXhxR3U1Sm5zVXAxektyZ2gvQTZuajljPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\akg5WXhxR3U1Sm5zVXAxektyZ2gvQTZuajljPQ==\clients folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\akg5WXhxR3U1Sm5zVXAxektyZ2gvQTZuajljPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\akg5WXhxR3U1Sm5zVXAxektyZ2gvQTZuajljPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\a21PdjVTa3g3WHRVaDJtaW8xV1RUaCtBbEdNPQ==\icons folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\a21PdjVTa3g3WHRVaDJtaW8xV1RUaCtBbEdNPQ==\channels folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache\a21PdjVTa3g3WHRVaDJtaW8xV1RUaCtBbEdNPQ== folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client\cache folder moved successfully.
C:\Users\mark\AppData\Roaming\TS3Client folder moved successfully.
C:\Users\mark\AppData\Roaming\TuneUp Software\TU2012\Backups folder moved successfully.
C:\Users\mark\AppData\Roaming\TuneUp Software\TU2012 folder moved successfully.
C:\Users\mark\AppData\Roaming\TuneUp Software folder moved successfully.
C:\Users\mark\AppData\Roaming\Vibosoft\Vibosoft iPhone SMS+Contacts Recovery folder moved successfully.
C:\Users\mark\AppData\Roaming\Vibosoft\IOS_RECOVERY_VIBO folder moved successfully.
C:\Users\mark\AppData\Roaming\Vibosoft folder moved successfully.
C:\Users\mark\AppData\Roaming\WindSolutions\CopyTransPhoto folder moved successfully.
C:\Users\mark\AppData\Roaming\WindSolutions\CopyTransContacts\webcache folder moved successfully.
C:\Users\mark\AppData\Roaming\WindSolutions\CopyTransContacts\mbcache\c04f9a65d1b6f2f8861b5264b9df501c02e83448 folder moved successfully.
C:\Users\mark\AppData\Roaming\WindSolutions\CopyTransContacts\mbcache folder moved successfully.
C:\Users\mark\AppData\Roaming\WindSolutions\CopyTransContacts folder moved successfully.
C:\Users\mark\AppData\Roaming\WindSolutions folder moved successfully.
========== FILES ==========
C:\Windows\46ED2B6485C74E1F920CA555B21F2E4C.TMP folder moved successfully.
File move failed. C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll scheduled to be moved on reboot.
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 moved successfully.
C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 moved successfully.
C:\ProgramData\.zreglib moved successfully.
========== COMMANDS ==========
Error: Unable to interpret <[startexplorer]> in the current context!

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: mark
->Temp folder emptied: 249376 bytes
->Temporary Internet Files folder emptied: 128 bytes
->Java cache emptied: 802593 bytes
->Flash cache emptied: 317 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 121609 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 05092016_124833

Files\Folders moved on Reboot...
File move failed. C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll scheduled to be moved on reboot.
C:\Users\mark\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\mark\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp\_avast_\AvastLock.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\SafeZone Installer\safezone_installer_20160508202512.log scheduled to be moved on reboot.
File move failed. C:\Windows\temp\SafeZone Installer\safezone_installer_20160508202515.log scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...


I had to split it up, i could not get the whole log in one post or upload it.

Sorry if i shouldnt of uploaded the first file.
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am

Re: Broken IE / Win update

Unread postby markuk86 » May 9th, 2016, 8:20 am

Do you see any changes in computer behavior?

A few settings have changed i think. The only one i notice at the moment is my teamspeak user has reset.

Could you give me a little brief of what that stuff actually did?:)

Thanks again for this help!
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am

Re: Broken IE / Win update

Unread postby pgmigg » May 9th, 2016, 11:27 am

Hello markuk86,

Could you give me a little brief of what that stuff actually did?:)
Even a brief description will be too long... :D

Right now I would like to receive couple fresh scans and ask you to run Internet Explorer and check how it is working...

Step 1.
Fresh FRST64 Scan
You should still have FRST64.exe on your desktop.
  1. Right-click FRST64.exe and select "Run as administrator..." to run it.
  2. When the tool opens click Yes to the disclaimer if it is occurred.
  3. Please be sure that 90 Days Files check box under Optional Scan section is checked.
  4. Please be sure that Addition.txt check box under Optional Scan section is unchecked.
  5. Press Scan button. When finished a log will be created, FRST.txt.
  6. Please post the content of the FRST.txt in your next reply.

Step 2.
Fresh OTL Scan
You should still have OTL.exe on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
  1. Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
  2. Under Output, ensure that Standard Output is selected.
  3. Check the boxes labeled:
    • Include 64 bit scans
    • Scan All Users
    • LOP check
    • Processes ---> All
    • Services ---> All
    • Modules ---> All
    • Drivers ---> All
    • Extra Registry ---> Use SafeList
  4. Click on Run Scan at the top left hand corner.
  5. When done, one Notepad file OTL.txt <-- Will be opened, maximized
  6. Please post the content of OTL.txt file ONLY in your next reply.

Please post each log separately to prevent it being cut off by the forum post size limiter.
Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections....

Please don't post your logs as attached files!

Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Results after checking of Internet Explorer behaviour.
  3. Contents of the FRST.txt log file after fresh FRST scan
  4. Contents of a OTL.txt log file after OTL fresh scan
  5. Do you see any changes in computer behavior?

Thanks,
pgmigg

Failure to post replies within 72 hours will result in this thread being closed
User avatar
pgmigg
Admin/Teacher
Admin/Teacher
 
Posts: 5457
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Broken IE / Win update

Unread postby markuk86 » May 9th, 2016, 12:20 pm

hello again

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-05-2016
Ran by mark (administrator) on MARK-PC (09-05-2016 17:13:01)
Running from C:\Users\mark\Desktop
Loaded Profiles: mark (Available Profiles: mark)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files (x86)\Common Files\aunhelper\aunhelper.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Common Files\aunhelper\worker.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(VIA Technologies, Inc.) C:\VIA_XHCI\usb3Monitor.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Valve Corporation) E:\Steam\Steam.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Piriform Ltd) E:\CCleaner\CCleaner64.exe
(Valve Corporation) E:\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(Razer, Inc.) C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\rzcefrenderprocess.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(TeamSpeak Systems GmbH) E:\TS3\ts3client_win64.exe
(Valve Corporation) E:\Steam\bin\steamwebhelper.exe
() E:\MSI Afterburner\MSIAfterburner.exe
() E:\RivaTuner Statistics Server\RTSS.exe
() E:\RivaTuner Statistics Server\EncoderServer.exe
() E:\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [VIAxHCUtl] => C:\VIA_XHCI\usb3Monitor.exe [331776 2011-07-12] (VIA Technologies, Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-03-08] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-03-19] (Apple Inc.)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [595616 2016-04-21] (Razer Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7391632 2016-05-08] (AVAST Software)
HKU\S-1-5-21-3640800009-1063320712-4824981-1002\...\Run: [Steam] => E:\Steam\steam.exe [3077712 2016-04-30] (Valve Corporation)
HKU\S-1-5-21-3640800009-1063320712-4824981-1002\...\Run: [CCleaner Monitoring] => E:\CCleaner\CCleaner64.exe [8641240 2016-02-12] (Piriform Ltd)
HKU\S-1-5-21-3640800009-1063320712-4824981-1002\...\Policies\Explorer: [NoInternetIcon] 0
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-05-08] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [.DEFAULT] => Proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:53914;https=127.0.0.1:53914
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{4BDDE909-497E-466E-94E5-59D0D335FCC0}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-3640800009-1063320712-4824981-1002\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-05-08] (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-06] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-05-08] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-01-16] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-06] (Oracle Corporation)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {82E5DF24-51E8-47CD-864A-F4BD5005AA73} hxxps://www.icloud.com/system/iCloud.cab
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.52 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2011-12-02] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2011-12-02] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-06] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-12-19] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-03-08] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-03-08] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\mark\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall)
FF Plugin-x32: @raidcall.kr/RCplugin -> C:\Users\mark\AppData\Roaming\RCKR\plugins\nprcplugin.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> E:\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-02-27] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3640800009-1063320712-4824981-1002: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-04-21] ()
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-05-08]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome:
=======
CHR Profile: C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-09]
CHR Extension: (Google Docs) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-17]
CHR Extension: (Google Drive) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-24]
CHR Extension: (YouTube) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Google Search) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-06]
CHR Extension: (Google Docs Offline) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-11]
CHR Extension: (Gmail) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-11]
CHR Profile: C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Google Slides) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-18]
CHR Extension: (Google Docs) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-18]
CHR Extension: (Google Drive) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-18]
CHR Extension: (YouTube) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-18]
CHR Extension: (Google Sheets) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-18]
CHR Extension: (Google Docs Offline) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR Extension: (Gmail) - C:\Users\mark\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-18]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-05-08]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-07] ()
R2 aunhelper; C:\Program Files (x86)\Common Files\aunhelper\aunhelper.exe [457808 2015-11-05] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-05-08] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1362464 2016-04-19] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-03-08] (NVIDIA Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-03-08] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-03-08] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-03-08] (NVIDIA Corporation)
S3 Origin Client Service; E:\Origin\OriginClientService.exe [2119688 2016-04-02] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2015-03-22] ()
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [65176 2016-04-08] (Razer Inc.)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [188072 2015-11-05] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21616 2011-11-02] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-05-08] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-05-08] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-05-08] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-05-08] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-05-08] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-05-08] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-05-08] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-05-08] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287528 2016-05-08] (AVAST Software)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-08-14] (AVG Technologies)
S3 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [30264 2015-09-11] (Disc Soft Ltd)
S3 dtultrausbbus; C:\Windows\System32\DRIVERS\dtultrausbbus.sys [47160 2015-09-09] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-01-16] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-03-08] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2016-03-08] (NVIDIA Corporation)
R3 RTCore64; E:\MSI Afterburner\RTCore64.sys [13480 2014-05-19] ()
S3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [51224 2016-04-07] (Razer Inc)
R3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [47640 2016-04-07] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-09-22] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [130880 2015-12-14] (Razer, Inc.)
R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [205312 2012-01-20] (VIA Technologies, Inc.)
R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [254464 2012-01-20] (VIA Technologies, Inc.)
S3 avchv; system32\DRIVERS\avchv.sys [X]
S3 cpuz134; \??\C:\Users\mark\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Three Months Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-09 17:13 - 2016-05-09 17:13 - 00019045 _____ C:\Users\mark\Desktop\FRST.txt
2016-05-09 13:24 - 2016-05-09 13:24 - 00000000 ____D C:\Users\mark\AppData\Roaming\raidcall
2016-05-09 13:09 - 2016-05-09 17:09 - 00000000 ____D C:\Users\mark\AppData\Roaming\TS3Client
2016-05-09 13:08 - 2016-05-09 13:08 - 00045146 _____ C:\Users\mark\Downloads\Addition.txt
2016-05-09 13:02 - 2016-05-09 13:02 - 00419600 _____ C:\Users\mark\Downloads\TDSSKiller.3.1.0.9_09.05.2016_12.41.04_log.txt
2016-05-09 12:48 - 2016-05-09 12:48 - 00000000 ____D C:\_OTL
2016-05-09 12:40 - 2016-05-09 12:40 - 04727984 _____ (Kaspersky Lab ZAO) C:\Users\mark\Desktop\tdsskiller.exe
2016-05-09 01:35 - 2016-05-09 01:35 - 00602112 _____ (OldTimer Tools) C:\Users\mark\Desktop\OTL.exe
2016-05-09 01:31 - 2016-05-09 01:31 - 01610816 _____ (Malwarebytes) C:\Users\mark\Desktop\JRT.exe
2016-05-09 01:27 - 2016-05-09 01:27 - 03615296 _____ C:\Users\mark\Downloads\adwcleaner_5.115.exe
2016-05-08 20:25 - 2016-05-08 20:25 - 00037144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-05-08 20:25 - 2016-05-08 20:25 - 00003888 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1462735515
2016-05-08 20:25 - 2016-05-08 20:25 - 00001037 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-05-08 20:25 - 2016-05-08 20:25 - 00001037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-05-08 20:24 - 2016-05-08 20:25 - 00000000 ____D C:\ProgramData\AVAST Software
2016-05-08 20:24 - 2016-05-08 20:25 - 00000000 ____D C:\Program Files\AVAST Software
2016-05-08 20:24 - 2016-05-08 20:24 - 05168776 _____ (AVAST Software) C:\Users\mark\Downloads\avast_free_antivirus_setup_online.exe
2016-05-08 20:24 - 2016-05-08 20:24 - 01070904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-05-08 20:24 - 2016-05-08 20:24 - 00465792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-05-08 20:24 - 2016-05-08 20:24 - 00398152 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-05-08 20:24 - 2016-05-08 20:24 - 00287528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-05-08 20:24 - 2016-05-08 20:24 - 00166432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-05-08 20:24 - 2016-05-08 20:24 - 00107792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-05-08 20:24 - 2016-05-08 20:24 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-05-08 20:24 - 2016-05-08 20:24 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-05-08 20:24 - 2016-05-08 20:24 - 00052184 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-05-08 20:24 - 2016-05-08 20:24 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-05-08 20:24 - 2016-05-08 20:24 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-05-08 20:24 - 2016-05-08 20:24 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-05-08 20:24 - 2016-05-08 20:24 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2016-05-08 20:24 - 2016-05-08 20:24 - 00000000 ____D C:\Users\mark\AppData\Roaming\AVAST Software
2016-05-08 20:24 - 2016-05-08 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-05-08 20:24 - 2016-05-08 20:24 - 00000000 ____D C:\Program Files\Common Files\AV
2016-05-08 20:21 - 2016-05-08 20:21 - 00468480 _____ () C:\Users\mark\Desktop\CKScanner.exe
2016-05-08 00:59 - 2016-05-08 20:14 - 00000057 _____ C:\Users\mark\Desktop\New Text Document (2).txt
2016-05-07 10:36 - 2016-05-09 17:13 - 00000000 ____D C:\FRST
2016-05-07 10:30 - 2016-05-07 10:30 - 02379264 _____ (Farbar) C:\Users\mark\Desktop\FRST64.exe
2016-05-07 10:23 - 2016-05-09 01:26 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2016-05-07 03:06 - 2016-05-07 03:06 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avchv_01009.Wdf
2016-05-07 03:02 - 2016-05-09 01:29 - 00000000 ____D C:\AdwCleaner
2016-05-06 18:08 - 2016-03-31 20:25 - 00394952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-05-06 18:08 - 2016-03-31 19:41 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-05-06 18:08 - 2016-03-31 01:54 - 25817600 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-05-06 18:08 - 2016-03-31 01:40 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-05-06 18:08 - 2016-03-31 01:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-05-06 18:08 - 2016-03-31 01:31 - 02892800 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-05-06 18:08 - 2016-03-31 01:28 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-05-06 18:08 - 2016-03-31 01:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-05-06 18:08 - 2016-03-31 01:27 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-05-06 18:08 - 2016-03-31 01:27 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-05-06 18:08 - 2016-03-31 01:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-05-06 18:08 - 2016-03-31 01:25 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-05-06 18:08 - 2016-03-31 01:22 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-05-06 18:08 - 2016-03-31 01:21 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-05-06 18:08 - 2016-03-31 01:19 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-05-06 18:08 - 2016-03-31 01:17 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-05-06 18:08 - 2016-03-31 01:17 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-05-06 18:08 - 2016-03-31 01:17 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-05-06 18:08 - 2016-03-31 01:17 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-05-06 18:08 - 2016-03-31 01:11 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-05-06 18:08 - 2016-03-31 01:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-05-06 18:08 - 2016-03-31 01:03 - 20352512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-05-06 18:08 - 2016-03-31 01:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-05-06 18:08 - 2016-03-31 01:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-05-06 18:08 - 2016-03-31 00:59 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-05-06 18:08 - 2016-03-31 00:57 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-05-06 18:08 - 2016-03-31 00:56 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-05-06 18:08 - 2016-03-31 00:55 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-05-06 18:08 - 2016-03-31 00:53 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-05-06 18:08 - 2016-03-31 00:53 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-05-06 18:08 - 2016-03-31 00:52 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-05-06 18:08 - 2016-03-31 00:52 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-05-06 18:08 - 2016-03-31 00:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-05-06 18:08 - 2016-03-31 00:52 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-05-06 18:08 - 2016-03-31 00:51 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-05-06 18:08 - 2016-03-31 00:48 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-05-06 18:08 - 2016-03-31 00:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-05-06 18:08 - 2016-03-31 00:46 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-05-06 18:08 - 2016-03-31 00:45 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-05-06 18:08 - 2016-03-31 00:45 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-05-06 18:08 - 2016-03-31 00:45 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-05-06 18:08 - 2016-03-31 00:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-05-06 18:08 - 2016-03-31 00:43 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-05-06 18:08 - 2016-03-31 00:43 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-05-06 18:08 - 2016-03-31 00:42 - 02131968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-05-06 18:08 - 2016-03-31 00:42 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-05-06 18:08 - 2016-03-31 00:39 - 15415808 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-05-06 18:08 - 2016-03-31 00:38 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-05-06 18:08 - 2016-03-31 00:34 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-05-06 18:08 - 2016-03-31 00:33 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-05-06 18:08 - 2016-03-31 00:31 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-05-06 18:08 - 2016-03-31 00:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-05-06 18:08 - 2016-03-31 00:30 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-05-06 18:08 - 2016-03-31 00:30 - 02596864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-05-06 18:08 - 2016-03-31 00:30 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-05-06 18:08 - 2016-03-31 00:29 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-05-06 18:08 - 2016-03-31 00:24 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-05-06 18:08 - 2016-03-31 00:23 - 02056192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-05-06 18:08 - 2016-03-31 00:23 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-05-06 18:08 - 2016-03-31 00:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-05-06 18:08 - 2016-03-31 00:21 - 13811712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-05-06 18:08 - 2016-03-31 00:18 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-05-06 18:08 - 2016-03-31 00:06 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-05-06 18:08 - 2016-03-31 00:05 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-05-06 18:08 - 2016-03-31 00:02 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-05-06 18:08 - 2016-03-31 00:00 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-05-06 17:22 - 2016-01-22 07:18 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2016-05-06 17:22 - 2016-01-22 07:18 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2016-05-06 17:22 - 2016-01-22 07:17 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-05-06 17:22 - 2016-01-22 07:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2016-05-06 17:22 - 2016-01-22 07:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll
2016-05-06 17:22 - 2016-01-22 07:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2016-05-06 17:22 - 2016-01-22 07:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2016-05-06 17:09 - 2016-02-05 02:19 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2016-05-06 17:09 - 2016-02-04 19:41 - 00296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
2016-05-06 17:00 - 2016-03-29 18:53 - 03216896 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-05-06 17:00 - 2016-03-18 00:04 - 05551336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-05-06 17:00 - 2016-03-18 00:04 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-05-06 17:00 - 2016-03-18 00:04 - 00154344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-05-06 17:00 - 2016-03-18 00:04 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-05-06 17:00 - 2016-03-18 00:01 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-05-06 17:00 - 2016-03-18 00:01 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-05-06 17:00 - 2016-03-17 23:58 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-05-06 17:00 - 2016-03-17 23:58 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-05-06 17:00 - 2016-03-17 23:57 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-05-06 17:00 - 2016-03-17 23:57 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-05-06 17:00 - 2016-03-17 23:57 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-05-06 17:00 - 2016-03-17 23:57 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-05-06 17:00 - 2016-03-17 23:57 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-05-06 17:00 - 2016-03-17 23:56 - 02084864 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-05-06 17:00 - 2016-03-17 23:56 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-05-06 17:00 - 2016-03-17 23:54 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-05-06 17:00 - 2016-03-17 23:54 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-05-06 17:00 - 2016-03-17 23:54 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-05-06 17:00 - 2016-03-17 23:54 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-05-06 17:00 - 2016-03-17 23:53 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-05-06 17:00 - 2016-03-17 23:53 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-05-06 17:00 - 2016-03-17 23:53 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-05-06 17:00 - 2016-03-17 23:53 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:50 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-05-06 17:00 - 2016-03-17 23:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-05-06 17:00 - 2016-03-17 23:33 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-05-06 17:00 - 2016-03-17 23:31 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-05-06 17:00 - 2016-03-17 23:31 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-05-06 17:00 - 2016-03-17 23:31 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-05-06 17:00 - 2016-03-17 23:31 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-05-06 17:00 - 2016-03-17 23:31 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-05-06 17:00 - 2016-03-17 23:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-05-06 17:00 - 2016-03-17 23:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-05-06 17:00 - 2016-03-17 23:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-05-06 17:00 - 2016-03-17 23:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-05-06 17:00 - 2016-03-17 23:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-05-06 17:00 - 2016-03-17 23:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-05-06 17:00 - 2016-03-17 23:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-05-06 17:00 - 2016-03-17 23:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-05-06 17:00 - 2016-03-17 23:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-05-06 17:00 - 2016-03-17 23:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-05-06 17:00 - 2016-03-17 23:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-05-06 17:00 - 2016-03-17 23:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-05-06 17:00 - 2016-03-17 23:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 23:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 22:53 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-05-06 17:00 - 2016-03-17 22:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-05-06 17:00 - 2016-03-17 22:52 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-05-06 17:00 - 2016-03-17 22:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-05-06 17:00 - 2016-03-17 22:44 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-05-06 17:00 - 2016-03-17 22:43 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-05-06 17:00 - 2016-03-17 22:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-05-06 17:00 - 2016-03-17 22:38 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-05-06 17:00 - 2016-03-17 22:37 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-05-06 17:00 - 2016-03-17 22:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-05-06 17:00 - 2016-03-17 22:35 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-05-06 17:00 - 2016-03-17 22:35 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-05-06 17:00 - 2016-03-17 22:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-05-06 17:00 - 2016-03-17 22:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-05-06 17:00 - 2016-03-17 22:30 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-05-06 17:00 - 2016-03-17 22:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-05-06 17:00 - 2016-03-17 22:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-05-06 17:00 - 2016-03-17 22:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 22:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 22:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-05-06 17:00 - 2016-03-17 22:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-05-06 17:00 - 2016-03-16 01:16 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-05-06 17:00 - 2016-03-16 01:16 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-05-06 17:00 - 2016-03-16 00:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2016-05-06 17:00 - 2016-03-11 19:57 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-05-06 17:00 - 2016-03-11 19:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-05-06 17:00 - 2016-03-06 19:53 - 01885696 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-05-06 17:00 - 2016-03-06 19:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2016-05-06 17:00 - 2016-03-06 19:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2016-05-06 17:00 - 2016-03-06 19:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2016-05-06 17:00 - 2016-02-12 19:52 - 03169792 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2016-05-06 17:00 - 2016-02-12 19:52 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2016-05-06 17:00 - 2016-02-12 19:52 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2016-05-06 17:00 - 2016-02-12 19:44 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2016-05-06 17:00 - 2016-02-12 19:39 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2016-05-06 17:00 - 2016-02-12 19:22 - 02610688 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-05-06 17:00 - 2016-02-12 19:19 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-05-06 17:00 - 2016-02-12 19:18 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-05-06 17:00 - 2016-02-12 19:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-05-06 17:00 - 2016-02-12 19:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2016-05-06 17:00 - 2016-02-12 19:18 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2016-05-06 17:00 - 2016-02-12 19:18 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2016-05-06 17:00 - 2016-02-12 19:06 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2016-05-06 17:00 - 2016-02-12 19:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2016-05-06 17:00 - 2016-02-12 19:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2016-05-06 17:00 - 2016-02-12 19:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2016-05-06 17:00 - 2016-02-09 10:57 - 14634496 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-05-06 17:00 - 2016-02-09 10:57 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2016-05-06 17:00 - 2016-02-09 10:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2016-05-06 17:00 - 2016-02-09 10:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2016-05-06 17:00 - 2016-02-09 10:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll
2016-05-06 17:00 - 2016-02-09 10:54 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2016-05-06 17:00 - 2016-02-09 10:51 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2016-05-06 17:00 - 2016-02-09 10:51 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-05-06 17:00 - 2016-02-09 10:13 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2016-05-06 17:00 - 2016-02-09 10:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2016-05-06 17:00 - 2016-02-09 10:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2016-05-06 17:00 - 2016-02-05 19:54 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-05-06 17:00 - 2016-02-05 19:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-05-06 17:00 - 2016-02-05 19:53 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-05-06 17:00 - 2016-02-05 19:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-05-06 17:00 - 2016-02-05 19:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-05-06 17:00 - 2016-02-05 19:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-05-06 17:00 - 2016-02-05 19:42 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-05-06 17:00 - 2016-02-05 18:48 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-05-06 17:00 - 2016-02-05 18:43 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-05-06 17:00 - 2016-02-05 18:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-05-06 17:00 - 2016-02-03 19:58 - 00862208 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2016-05-06 17:00 - 2016-02-03 19:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-05-06 17:00 - 2016-02-03 19:49 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2016-05-06 17:00 - 2016-02-03 19:43 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2016-05-06 17:00 - 2016-02-03 19:07 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2016-05-06 17:00 - 2016-01-07 18:42 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-05-06 17:00 - 2016-01-06 20:02 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2016-05-06 17:00 - 2016-01-06 20:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2016-05-06 17:00 - 2016-01-06 19:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2016-05-04 22:34 - 2016-05-04 22:38 - 00000099 _____ C:\Users\mark\Desktop\MARTYR.txt
2016-05-02 13:41 - 2016-05-02 13:41 - 00000000 ____D C:\Users\mark\AppData\Roaming\NVIDIA
2016-04-29 13:27 - 2016-04-29 13:27 - 00003903 _____ C:\Users\mark\Downloads\Engine.ini
2016-04-29 01:34 - 2016-05-08 20:24 - 00000610 _____ C:\Users\mark\Desktop\New Text Document.txt
2016-04-25 11:27 - 2016-04-25 11:27 - 01400792 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevicedll.dll
2016-04-11 09:14 - 2016-04-11 09:14 - 00516056 _____ (Razer Inc) C:\Windows\SysWOW64\rzaudiodll.dll
2016-04-11 09:14 - 2016-04-11 09:14 - 00161752 _____ (Razer Inc) C:\Windows\SysWOW64\rztouchdll.dll
2016-04-11 09:14 - 2016-04-11 09:14 - 00123352 _____ (Razer Inc) C:\Windows\SysWOW64\rzdisplaydll.dll
2016-04-11 09:14 - 2016-04-11 09:14 - 00110040 _____ (Razer Inc) C:\Windows\SysWOW64\rzvirtualdev.dll
2016-04-11 09:14 - 2016-04-11 09:14 - 00099288 _____ (Razer Inc) C:\Windows\SysWOW64\RzBTLE.dll
2016-04-11 09:14 - 2016-04-11 09:14 - 00097752 _____ (Razer Inc) C:\Windows\SysWOW64\rzdevinfo.dll
2016-04-08 03:52 - 2016-04-08 03:52 - 00099992 _____ (Razer Inc.) C:\Windows\system32\RzChromaSDK64.dll
2016-04-08 03:51 - 2016-04-08 03:51 - 00088728 _____ (Razer Inc.) C:\Windows\SysWOW64\RzChromaSDK.dll
2016-04-08 03:51 - 2016-04-08 03:51 - 00042144 _____ (Razer Inc.) C:\Windows\SysWOW64\RzAPIChromaSDK.dll
2016-04-07 12:56 - 2016-04-07 12:56 - 00203800 _____ (Razer Inc) C:\Windows\system32\Drivers\rzudd.sys
2016-04-07 12:55 - 2016-04-07 12:55 - 00051224 _____ (Razer Inc) C:\Windows\system32\Drivers\rzendpt.sys
2016-04-07 12:55 - 2016-04-07 12:55 - 00047640 _____ (Razer Inc) C:\Windows\system32\Drivers\rzmpos.sys
2016-04-06 15:12 - 2016-04-13 15:33 - 00000000 ____D C:\Users\mark\Desktop\pwnage
2016-04-06 14:58 - 2016-04-06 14:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-04-06 14:58 - 2016-04-06 14:58 - 00000000 ____D C:\Program Files\iPod
2016-04-06 14:57 - 2016-04-06 14:58 - 00000000 ____D C:\Program Files\iTunes
2016-04-06 14:57 - 2016-04-06 14:57 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2016-04-06 14:57 - 2016-04-06 14:57 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2016-04-03 15:54 - 2016-05-07 04:32 - 00000000 ____D C:\Users\mark\AppData\Local\ElevatedDiagnostics
2016-03-22 12:58 - 2016-03-25 08:29 - 00000000 ____D C:\Users\mark\AppData\Local\NVIDIA Corporation
2016-03-22 12:57 - 2016-03-25 08:29 - 00000000 ____D C:\Users\mark\AppData\Local\NVIDIA
2016-03-22 12:57 - 2016-03-25 08:29 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-22 12:57 - 2016-03-22 12:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-03-22 12:57 - 2016-03-22 12:57 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-22 12:57 - 2016-03-08 11:07 - 01903344 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2016-03-22 12:57 - 2016-03-08 11:07 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2016-03-22 12:57 - 2016-03-08 11:07 - 01571624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2016-03-22 12:57 - 2016-03-08 11:07 - 01316184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2016-03-22 12:57 - 2016-03-08 11:07 - 00213952 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2016-03-22 12:57 - 2016-03-08 11:07 - 00201664 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2016-03-22 12:57 - 2016-03-08 07:27 - 06369728 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2016-03-22 12:57 - 2016-03-08 07:27 - 02994232 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2016-03-22 12:57 - 2016-03-08 07:27 - 02561472 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2016-03-22 12:57 - 2016-03-08 07:27 - 01264064 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2016-03-22 12:57 - 2016-03-08 07:27 - 00532536 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2016-03-22 12:57 - 2016-03-08 07:27 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2016-03-22 12:57 - 2016-03-08 07:27 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2016-03-22 12:57 - 2016-03-08 07:27 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2016-03-22 12:57 - 2016-03-08 07:15 - 00110016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2016-03-22 12:57 - 2016-03-07 05:23 - 06203411 _____ C:\Windows\system32\nvcoproc.bin
2016-03-22 12:56 - 2016-03-22 12:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-22 12:56 - 2016-03-08 11:07 - 42968120 _____ C:\Windows\system32\nvcompiler.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 37609528 _____ C:\Windows\SysWOW64\nvcompiler.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 22932928 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 21313024 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 20854680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 18990976 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 18879544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 17725040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 17318184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 17246680 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 16439328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 14128496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 12564024 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2016-03-22 12:56 - 2016-03-08 11:07 - 10546944 _____ C:\Windows\system32\nvptxJitCompiler.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 08658120 _____ C:\Windows\SysWOW64\nvptxJitCompiler.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 03711024 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 03283896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 03233336 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 02808768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 01924152 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436451.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 01572496 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 01571776 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436451.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00956984 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00886840 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00749504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00693816 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00678520 _____ C:\Windows\system32\nvfatbinaryLoader.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00571912 _____ C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00502080 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00473056 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00423360 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00423080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00391632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00379448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00205456 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2016-03-22 12:56 - 2016-03-08 11:07 - 00175552 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00151368 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00099472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00090768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00047760 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2016-03-22 12:56 - 2016-03-08 11:07 - 00039240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2016-03-22 12:56 - 2016-03-08 11:07 - 00036743 _____ C:\Windows\system32\nvinfo.pb
2016-03-22 12:56 - 2016-03-08 11:07 - 00000139 _____ C:\Windows\SysWOW64\nv-vk32.json
2016-03-22 12:56 - 2016-03-08 11:07 - 00000139 _____ C:\Windows\system32\nv-vk64.json
2016-03-22 11:47 - 2016-03-22 11:47 - 00189112 _____ (Power Admin LLC) C:\Windows\PAExec.exe
2016-03-17 08:39 - 2016-03-17 08:39 - 00000000 ____D C:\ProgramData\.mono
2016-03-14 12:55 - 2016-03-14 12:55 - 00376832 _____ (MARX CryptoTech LP ) C:\Windows\SysWOW64\MPIWIN32.DLL
2016-03-14 12:55 - 2016-03-14 12:55 - 00000000 ____D C:\Windows\SysWOW64\Temp
2016-03-07 01:57 - 2016-03-07 01:58 - 00000000 ____D C:\Users\mark\Desktop\rcon
2016-03-06 21:47 - 2016-03-07 01:59 - 00000166 _____ C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2016-03-04 13:47 - 2016-03-26 17:21 - 00000000 ____D C:\Users\mark\Desktop\Rubbish
2016-03-03 09:47 - 2009-07-10 13:43 - 01589248 _____ C:\Windows\SysWOW64\libmysql_d.dll
2016-03-03 09:32 - 2016-03-03 09:32 - 00000000 ____D C:\ProgramData\dbdata
2016-02-19 19:59 - 2016-02-19 21:15 - 00000000 ____D C:\Users\mark\Documents\Navicat
2016-02-19 19:58 - 2016-03-03 09:47 - 00000599 _____ C:\Users\Public\Desktop\Navicat Premium.lnk
2016-02-19 19:58 - 2016-02-19 19:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremiumSoft
2016-02-16 12:36 - 2016-02-16 12:36 - 00059496 ____R (PalmSource, Inc) C:\Windows\SysWOW64\USBPort.dll
2016-02-16 12:36 - 2016-02-16 12:36 - 00059496 ____R (PalmSource, Inc) C:\Windows\SysWOW64\PalmDevC.dll

==================== Three Months Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-05-09 17:08 - 2014-07-21 20:07 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-09 16:28 - 2014-07-17 00:34 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-05-09 14:17 - 2015-12-22 21:10 - 00000000 ____D C:\Users\mark\AppData\Local\CrashDumps
2016-05-09 13:14 - 2012-09-25 12:21 - 00000000 ____D C:\World of Warcraft
2016-05-09 13:13 - 2014-03-12 23:40 - 00000000 ____D C:\Users\mark\AppData\Local\Battle.net
2016-05-09 12:58 - 2009-07-14 05:45 - 00006416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-05-09 12:58 - 2009-07-14 05:45 - 00006416 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-05-09 12:56 - 2009-07-14 06:13 - 00782470 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-09 12:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-05-09 12:50 - 2014-07-21 20:07 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-09 12:50 - 2014-05-09 18:12 - 00000000 ____D C:\ProgramData\NVIDIA
2016-05-09 12:50 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-05-09 12:48 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2016-05-09 12:45 - 2012-11-13 19:19 - 00000000 ____D C:\Users\mark\AppData\LocalLow\Temp
2016-05-08 20:39 - 2011-04-12 09:28 - 00000000 ____D C:\Program Files\Windows Journal
2016-05-08 20:39 - 2009-07-14 05:45 - 00479536 _____ C:\Windows\system32\FNTCACHE.DAT
2016-05-08 20:36 - 2013-08-17 02:25 - 00000000 ____D C:\Windows\system32\MRT
2016-05-08 20:33 - 2012-09-25 19:50 - 135176864 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-05-07 04:32 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2016-05-06 17:52 - 2014-04-12 02:10 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-05-06 17:17 - 2015-10-08 17:47 - 00000000 ____D C:\Users\mark\.oracle_jre_usage
2016-05-06 17:17 - 2014-04-20 10:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-05-06 17:17 - 2014-02-21 14:31 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-05-06 17:17 - 2013-12-07 02:01 - 00000000 ____D C:\Program Files (x86)\Java
2016-05-06 17:10 - 2014-03-23 12:55 - 00000000 ____D C:\ProgramData\Razer
2016-05-06 17:00 - 2015-11-13 01:09 - 00000000 ____D C:\Program Files (x86)\Razer Chroma SDK
2016-05-06 11:42 - 2009-07-14 06:08 - 00032620 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-04-28 21:10 - 2014-07-21 20:07 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-28 21:10 - 2014-07-21 20:07 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-04-24 15:40 - 2014-04-12 08:34 - 00000623 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-04-24 15:40 - 2014-04-12 08:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-04-21 15:05 - 2010-11-21 04:27 - 00453288 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-20 19:20 - 2014-07-27 16:15 - 00000000 ____D C:\Users\mark\AppData\Local\Arma 3
2016-04-17 19:32 - 2014-07-29 21:26 - 00000000 ____D C:\Users\mark\Documents\Arma 3 - Other Profiles
2016-04-14 18:04 - 2015-06-06 23:31 - 00000000 ____D C:\Users\mark\AppData\Roaming\vlc
2016-04-09 18:30 - 2013-11-09 15:18 - 00000000 ____D C:\ProgramData\Oracle

==================== Files in the root of some directories =======

2013-08-15 12:04 - 2013-08-15 12:38 - 0007859 _____ () C:\Users\mark\AppData\Roaming\pcouffin.cat
2013-08-15 12:04 - 2013-08-15 12:38 - 0001167 _____ () C:\Users\mark\AppData\Roaming\pcouffin.inf
2013-08-15 12:04 - 2013-08-15 12:38 - 0000055 _____ () C:\Users\mark\AppData\Roaming\pcouffin.log
2013-08-15 12:04 - 2013-08-15 12:38 - 0082816 _____ (VSO Software) C:\Users\mark\AppData\Roaming\pcouffin.sys
2013-02-11 20:17 - 2013-07-23 16:35 - 0093980 _____ () C:\Users\mark\AppData\Local\ars.cache
2013-02-11 20:17 - 2013-07-23 16:35 - 0843900 _____ () C:\Users\mark\AppData\Local\census.cache
2014-03-23 12:55 - 2014-03-23 12:55 - 0009144 _____ () C:\Users\mark\AppData\Local\CleanupUninstall.txt
2012-09-26 10:05 - 2012-09-26 10:05 - 0003072 _____ () C:\Users\mark\AppData\Local\file__0.localstorage
2013-02-11 20:14 - 2013-02-11 20:14 - 0000036 _____ () C:\Users\mark\AppData\Local\housecall.guid.cache
2014-05-07 21:46 - 2014-05-15 01:16 - 0007602 _____ () C:\Users\mark\AppData\Local\Resmon.ResmonCfg
2014-10-16 00:13 - 2014-10-16 00:13 - 0001955 _____ () C:\Users\mark\AppData\Local\Temp1.html
2014-10-16 00:04 - 2014-10-16 00:04 - 0007527 _____ () C:\Users\mark\AppData\Local\Temp12.html
2012-10-22 20:10 - 2012-10-22 20:10 - 0007750 _____ () C:\Users\mark\AppData\Local\Temp14.html
2014-10-16 00:13 - 2014-10-16 00:13 - 0005674 _____ () C:\Users\mark\AppData\Local\Temp6.html
2015-02-05 19:14 - 2015-02-05 19:14 - 0000000 _____ () C:\Users\mark\AppData\Local\{D9B3F901-E567-43FF-92F5-F79303278988}
2016-03-06 21:47 - 2016-03-07 01:59 - 0000166 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-04-28 14:33

==================== End of FRST.txt ============================
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am

Re: Broken IE / Win update

Unread postby markuk86 » May 9th, 2016, 12:22 pm

OTL logfile created on: 5/9/2016 5:15:14 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\mark\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18282)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

15.96 Gb Total Physical Memory | 13.59 Gb Available Physical Memory | 85.14% Memory free
31.92 Gb Paging File | 29.61 Gb Available in Paging File | 92.76% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111.79 Gb Total Space | 18.58 Gb Free Space | 16.62% Space Free | Partition Type: NTFS
Drive E: | 931.41 Gb Total Space | 562.52 Gb Free Space | 60.39% Space Free | Partition Type: NTFS
Drive F: | 223.57 Gb Total Space | 223.44 Gb Free Space | 99.94% Space Free | Partition Type: NTFS

Computer Name: MARK-PC | User Name: mark | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (All) ==========

PRC - [2016/05/09 01:35:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\mark\Desktop\OTL.exe
PRC - [2016/05/08 20:24:32 | 007,391,632 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2016/05/08 20:24:31 | 000,243,296 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2016/04/21 09:12:56 | 000,595,616 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
PRC - [2016/04/08 03:53:54 | 000,065,176 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
PRC - [2016/04/01 02:16:28 | 000,596,504 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
PRC - [2016/03/31 19:41:03 | 000,815,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
PRC - [2016/03/08 11:07:02 | 002,789,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2016/03/08 11:07:02 | 001,880,960 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2016/03/08 07:15:05 | 000,424,384 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2015/12/14 23:28:40 | 000,259,776 | ---- | M] (Razer, Inc.) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
PRC - [2015/12/14 21:16:22 | 000,272,064 | ---- | M] (Razer, Inc.) -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\rzcefrenderprocess.exe
PRC - [2015/12/14 00:48:02 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2015/11/05 19:19:26 | 000,457,808 | ---- | M] () -- C:\Program Files (x86)\Common Files\aunhelper\aunhelper.exe
PRC - [2015/11/05 19:19:26 | 000,064,592 | ---- | M] () -- C:\Program Files (x86)\Common Files\aunhelper\worker.exe
PRC - [2015/11/05 01:12:06 | 000,188,072 | ---- | M] () -- C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
PRC - [2015/03/22 23:13:42 | 000,076,152 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/08/13 09:44:22 | 000,105,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
PRC - [2011/12/16 20:30:40 | 000,363,800 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2011/12/16 20:30:38 | 000,277,784 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2011/12/16 19:02:56 | 000,161,560 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
PRC - [2011/07/12 09:14:26 | 000,331,776 | R--- | M] (VIA Technologies, Inc.) -- C:\VIA_XHCI\usb3Monitor.exe


========== Modules (All) ==========

MOD - [2016/05/09 12:33:28 | 001,301,984 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\AVAST Software\Avast\libeay32.dll
MOD - [2016/05/09 12:33:28 | 000,299,816 | ---- | M] (The OpenSSL Project, http://www.openssl.org/) -- C:\Program Files\AVAST Software\Avast\ssleay32.dll
MOD - [2016/05/09 12:30:12 | 000,479,168 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\defs\16050900\aswCmnBS.dll
MOD - [2016/05/09 12:30:12 | 000,459,472 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\defs\16050900\aswCmnIS.dll
MOD - [2016/05/09 12:30:12 | 000,136,840 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\defs\16050900\aswCmnOS.dll
MOD - [2016/05/09 12:30:12 | 000,066,128 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\defs\16050900\uiext.dll
MOD - [2016/05/09 01:35:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\mark\Desktop\OTL.exe
MOD - [2016/05/08 20:24:33 | 004,456,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\mfc110u.dll
MOD - [2016/05/08 20:24:33 | 000,875,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\msvcr110.dll
MOD - [2016/05/08 20:24:33 | 000,535,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_avast.vc110.crt_2036b14a11e83e4a_11.0.60610.1_none_1d37a43bbfe1dc9c\msvcp110.dll
MOD - [2016/05/08 20:24:33 | 000,222,064 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswJsFlt.dll
MOD - [2016/05/08 20:24:32 | 040,539,648 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\libcef.dll
MOD - [2016/05/08 20:24:32 | 007,391,632 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
MOD - [2016/05/08 20:24:32 | 000,123,344 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\log.dll
MOD - [2016/05/08 20:24:31 | 004,052,304 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\CommonRes.dll
MOD - [2016/05/08 20:24:31 | 003,411,256 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\Aavm4h.dll
MOD - [2016/05/08 20:24:31 | 001,080,656 | ---- | M] (Microsoft Corporation) -- C:\Program Files\AVAST Software\Avast\dbghelp.dll
MOD - [2016/05/08 20:24:31 | 001,064,080 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\ashBase.dll
MOD - [2016/05/08 20:24:31 | 000,957,104 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswAux.dll
MOD - [2016/05/08 20:24:31 | 000,882,360 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswData.dll
MOD - [2016/05/08 20:24:31 | 000,627,760 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\CommChannel.dll
MOD - [2016/05/08 20:24:31 | 000,618,936 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswSqLt.dll
MOD - [2016/05/08 20:24:31 | 000,479,680 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\ffl2.dll
MOD - [2016/05/08 20:24:31 | 000,456,848 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswProperty.dll
MOD - [2016/05/08 20:24:31 | 000,438,688 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\ashTask.dll
MOD - [2016/05/08 20:24:31 | 000,403,848 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswCmnIS.dll
MOD - [2016/05/08 20:24:31 | 000,374,752 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswCmnBS.dll
MOD - [2016/05/08 20:24:31 | 000,372,704 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\ashTaskEx.dll
MOD - [2016/05/08 20:24:31 | 000,338,432 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\2057\uiLangRes.dll
MOD - [2016/05/08 20:24:31 | 000,336,896 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AavmRpch.dll
MOD - [2016/05/08 20:24:31 | 000,307,744 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswLog.dll
MOD - [2016/05/08 20:24:31 | 000,242,848 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\event_manager.dll
MOD - [2016/05/08 20:24:31 | 000,206,408 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswUtil.dll
MOD - [2016/05/08 20:24:31 | 000,141,504 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswCmnOS.dll
MOD - [2016/05/08 20:24:31 | 000,135,816 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
MOD - [2016/05/08 20:24:31 | 000,113,440 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswRemoteCache.dll
MOD - [2016/05/08 20:24:31 | 000,090,096 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\event_manager_rpc.dll
MOD - [2016/05/08 20:24:31 | 000,089,584 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\avastIP.dll
MOD - [2016/05/08 20:24:31 | 000,074,496 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\aswEngLdr.dll
MOD - [2016/05/08 20:24:31 | 000,072,840 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\2057\Base.dll
MOD - [2016/05/08 20:24:30 | 002,172,592 | ---- | M] (GlavSoft LLC.) -- C:\Program Files\AVAST Software\Avast\aswAra.dll
MOD - [2016/05/06 17:17:07 | 000,773,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Java\jre1.8.0_91\bin\msvcr100.dll
MOD - [2016/05/06 17:17:07 | 000,462,400 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll
MOD - [2016/05/06 17:17:07 | 000,173,120 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll
MOD - [2016/05/05 17:54:42 | 001,377,208 | ---- | M] (NVIDIA Corporation) -- C:\Users\mark\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\Ontology.dll
MOD - [2016/04/27 12:21:58 | 003,209,088 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\HTMLayout.dll
MOD - [2016/04/26 11:05:28 | 000,143,824 | ---- | M] () -- C:\ProgramData\Razer\Synapse\CrashReporter\CrashRpt1402.dll
MOD - [2016/04/26 11:05:24 | 007,244,760 | ---- | M] (Razer Inc.) -- C:\ProgramData\Razer\Synapse\Devices\RazerConfigNative.dll
MOD - [2016/04/25 11:27:26 | 001,400,792 | ---- | M] (Razer Inc) -- C:\Windows\SysWOW64\rzdevicedll.dll
MOD - [2016/04/21 09:13:12 | 000,210,584 | ---- | M] (Razer Inc) -- C:\Program Files (x86)\Razer\Synapse\rzdetmgr.dll
MOD - [2016/04/21 09:12:56 | 000,595,616 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
MOD - [2016/04/21 09:12:56 | 000,079,528 | ---- | M] (Razer Inc) -- C:\Program Files (x86)\Razer\Synapse\RzEmilySettings.dll
MOD - [2016/04/11 09:14:30 | 000,516,056 | ---- | M] (Razer Inc) -- C:\Windows\SysWOW64\rzaudiodll.dll
MOD - [2016/04/11 09:14:30 | 000,161,752 | ---- | M] (Razer Inc) -- C:\Windows\SysWOW64\rztouchdll.dll
MOD - [2016/04/11 09:14:30 | 000,110,040 | ---- | M] (Razer Inc) -- C:\Windows\SysWOW64\rzvirtualdev.dll
MOD - [2016/04/11 09:14:30 | 000,097,752 | ---- | M] (Razer Inc) -- C:\Windows\SysWOW64\rzdevinfo.dll
MOD - [2016/04/08 03:51:34 | 000,042,144 | ---- | M] (Razer Inc.) -- C:\Windows\SysWOW64\RzAPIChromaSDK.dll
MOD - [2016/04/01 02:16:28 | 000,596,504 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
MOD - [2016/03/31 19:41:03 | 000,815,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
MOD - [2016/03/31 01:03:51 | 020,352,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mshtml.dll
MOD - [2016/03/31 00:51:20 | 002,285,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\iertutil.dll
MOD - [2016/03/31 00:46:41 | 000,476,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ieui.dll
MOD - [2016/03/31 00:30:42 | 004,611,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\jscript9.dll
MOD - [2016/03/31 00:21:50 | 013,811,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ieframe.dll
MOD - [2016/03/31 00:05:23 | 002,121,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wininet.dll
MOD - [2016/03/31 00:03:39 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\IEShims.dll
MOD - [2016/03/31 00:02:17 | 001,311,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\urlmon.dll
MOD - [2016/03/31 00:00:46 | 000,710,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ieapfltr.dll
MOD - [2016/03/30 23:57:48 | 000,285,696 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Internet Explorer\ieproxy.dll
MOD - [2016/03/29 19:25:53 | 001,627,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be\GdiPlus.dll
MOD - [2016/03/17 23:33:29 | 001,314,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdll.dll
MOD - [2016/03/17 23:31:09 | 001,114,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\kernel32.dll
MOD - [2016/03/17 23:31:09 | 000,666,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rpcrt4.dll
MOD - [2016/03/17 23:31:09 | 000,275,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\KernelBase.dll
MOD - [2016/03/17 23:31:09 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sspicli.dll
MOD - [2016/03/17 23:30:00 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srclient.dll
MOD - [2016/03/17 23:29:26 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\secur32.dll
MOD - [2016/03/17 23:29:24 | 000,251,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\schannel.dll
MOD - [2016/03/17 23:28:21 | 001,414,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ole32.dll
MOD - [2016/03/17 23:27:53 | 000,223,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ncrypt.dll
MOD - [2016/03/17 23:25:00 | 000,017,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\credssp.dll
MOD - [2016/03/17 23:24:24 | 000,644,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\advapi32.dll
MOD - [2016/03/17 22:29:13 | 000,036,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptbase.dll
MOD - [2016/03/16 00:53:30 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samlib.dll
MOD - [2016/03/08 11:07:02 | 016,439,328 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWOW64\nvwgf2um.dll
MOD - [2016/03/08 11:07:02 | 014,128,496 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWOW64\nvd3dum.dll
MOD - [2016/03/08 11:07:02 | 003,283,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWOW64\nvapi.dll
MOD - [2016/03/08 11:07:02 | 002,789,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
MOD - [2016/03/08 11:07:02 | 001,571,624 | ---- | M] (NVIDIA Corporation) -- C:\Windows\SysWOW64\nvspcap.dll
MOD - [2016/03/08 11:07:02 | 000,020,352 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
MOD - [2016/03/08 07:16:26 | 000,721,952 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI.dll
MOD - [2016/02/05 19:50:53 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\lpk.dll
MOD - [2016/02/05 19:42:42 | 000,010,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dciman32.dll
MOD - [2016/02/03 19:49:27 | 000,572,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleaut32.dll
MOD - [2015/12/14 23:28:45 | 000,384,192 | ---- | M] (Razer, Inc.) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\RzWinMgrSrv.dll
MOD - [2015/12/14 23:28:44 | 000,267,456 | ---- | M] (Razer, Inc.) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\Rzlogger.dll
MOD - [2015/12/14 23:28:44 | 000,149,184 | ---- | M] (Razer, Inc.) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerOvlInput.dll
MOD - [2015/12/14 23:28:40 | 000,259,776 | ---- | M] (Razer, Inc.) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
MOD - [2015/12/14 21:16:24 | 000,305,664 | ---- | M] (Razer Inc.) -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\gamescannerclientlib.dll
MOD - [2015/12/14 21:16:24 | 000,305,664 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\client\GameScannerClientLib.dll
MOD - [2015/12/14 21:16:24 | 000,267,456 | ---- | M] (Razer, Inc.) -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\rzlogger.dll
MOD - [2015/12/14 21:16:24 | 000,174,272 | ---- | M] (Razer, Inc.) -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\rzwinmgrcli.dll
MOD - [2015/12/14 21:16:22 | 000,559,296 | ---- | M] (Razer, Inc.) -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\rzcefingamelib.dll
MOD - [2015/12/14 21:16:22 | 000,272,064 | ---- | M] (Razer, Inc.) -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\rzcefrenderprocess.exe
MOD - [2015/12/08 22:52:53 | 000,312,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gdi32.dll
MOD - [2015/11/10 19:39:18 | 001,251,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\DWrite.dll
MOD - [2015/11/10 19:37:39 | 000,833,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\user32.dll
MOD - [2015/11/03 19:56:18 | 000,627,712 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\usp10.dll
MOD - [2015/09/23 14:08:50 | 000,251,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcryptprimitives.dll
MOD - [2015/08/27 22:30:54 | 009,994,752 | ---- | M] (The ICU Project) -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\cef\icudt.dll
MOD - [2015/08/27 22:30:54 | 000,911,360 | ---- | M] () -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\cef\libglesv2.dll
MOD - [2015/08/27 22:30:52 | 040,622,592 | ---- | M] () -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\cef\libcef.dll
MOD - [2015/08/27 22:30:52 | 003,231,696 | ---- | M] (Microsoft Corporation) -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\cef\d3dcompiler_46.dll
MOD - [2015/08/27 22:30:52 | 000,134,144 | ---- | M] () -- C:\Users\mark\AppData\Local\Razer\InGameEngine\cache\RzSynapse\cef\libegl.dll
MOD - [2015/08/12 17:03:38 | 000,122,128 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Bonjour\mdnsNSP.dll
MOD - [2015/08/06 18:44:51 | 012,875,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shell32.dll
MOD - [2015/07/15 03:55:45 | 001,390,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msxml6.dll
MOD - [2015/07/07 03:35:32 | 000,033,280 | ---- | M] (Razer Inc.) -- C:\ProgramData\Razer\Synapse\Devices\RigCommonNative.dll
MOD - [2015/07/07 03:35:32 | 000,022,016 | ---- | M] (Razer Inc.) -- C:\ProgramData\Razer\Synapse\Devices\RigDependencyNative.dll
MOD - [2015/06/15 22:43:35 | 002,364,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msi.dll
MOD - [2015/06/07 00:08:44 | 000,012,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
MOD - [2015/05/12 08:13:00 | 000,079,872 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\Synapse\RzStorageIO.dll
MOD - [2015/04/24 18:56:58 | 000,530,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
MOD - [2015/04/24 18:54:13 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
MOD - [2015/02/03 04:12:48 | 000,179,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wintrust.dll
MOD - [2015/02/03 04:12:42 | 001,230,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WindowsCodecs.dll
MOD - [2015/02/03 04:12:14 | 001,174,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\crypt32.dll
MOD - [2015/02/03 04:12:14 | 001,005,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptui.dll
MOD - [2015/02/03 04:12:14 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptnet.dll
MOD - [2015/02/03 04:12:14 | 000,081,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cryptsp.dll
MOD - [2015/02/03 04:12:12 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\AudioSes.dll
MOD - [2015/01/17 03:30:42 | 000,828,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctf.dll
MOD - [2014/12/10 21:43:04 | 000,770,384 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\msvcr100.dll
MOD - [2014/12/10 21:43:04 | 000,421,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Razer\InGameEngine\32bit\msvcp100.dll
MOD - [2014/12/06 04:50:19 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nlaapi.dll
MOD - [2014/11/28 11:46:18 | 000,061,440 | ---- | M] (Razer) -- C:\Program Files (x86)\Razer\Synapse\RazerProtocolDLL.dll
MOD - [2014/08/20 20:48:11 | 000,018,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio49d6fefe#\e2bc7466bfb562cdc37c7de5fb176537\PresentationFramework-SystemXml.ni.dll
MOD - [2014/08/20 20:48:11 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio4b37ff64#\858ea27d6a6315f02c23755d1574e777\PresentationFramework-SystemXmlLinq.ni.dll
MOD - [2014/08/20 20:47:53 | 019,693,056 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\5402af8a63eab08e68cee5bb8c57ec43\System.ServiceModel.ni.dll
MOD - [2014/08/20 20:47:40 | 000,399,872 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\119dbb1f8385c58f2bee709d39bbb90d\System.Xml.Linq.ni.dll
MOD - [2014/08/20 20:47:37 | 000,190,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\896c51e0c895a7d3125856d303a3495f\UIAutomationTypes.ni.dll
MOD - [2014/08/20 20:26:26 | 018,813,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\dc7d3cf3ed23c066cf958991e0c5a2ee\PresentationFramework.ni.dll
MOD - [2014/08/20 20:26:23 | 012,894,208 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\5af458179c5c48dd9f400159b23c2398\System.Windows.Forms.ni.dll
MOD - [2014/08/20 20:26:23 | 000,470,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio1c9175f8#\ab78c8f8e5568f893308833861fc11d7\PresentationFramework.Aero.ni.dll
MOD - [2014/08/20 20:26:19 | 001,889,792 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\7b986cec878db3a6ab533de03fc552be\System.Xaml.ni.dll
MOD - [2014/08/20 20:26:18 | 011,025,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7ce7f36d6ddd95c15fa5bdefbfcbf0c\PresentationCore.ni.dll
MOD - [2014/08/20 20:26:18 | 001,644,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\35ff79b0dd6c57013ea52df5a95efd72\System.Drawing.ni.dll
MOD - [2014/08/20 20:26:18 | 000,122,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\3ae392116532056a505ee49002341288\SMDiagnostics.ni.dll
MOD - [2014/08/20 20:26:17 | 000,806,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\f56c031ccb3c19bfcdd668cdd0d0babc\System.ServiceModel.Internals.ni.dll
MOD - [2014/08/20 20:26:15 | 002,825,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\3a77639e6d14a90630ff1cce877134ae\System.Runtime.Serialization.ni.dll
MOD - [2014/08/20 20:26:14 | 006,990,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\d04bc8678d72be74f11365ced3c3cfe6\System.Core.ni.dll
MOD - [2014/08/20 20:26:13 | 007,662,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\66e122de5ff2bad83e6150461fd1f3a4\System.Xml.ni.dll
MOD - [2014/08/20 20:26:13 | 003,950,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\f1c8087380e2a00c4925353ff41819ef\WindowsBase.ni.dll
MOD - [2014/08/20 20:26:11 | 001,180,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\f12d4d2c367056d466b413892422cfb6\System.Management.ni.dll
MOD - [2014/08/20 20:26:11 | 000,976,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\aaadf3ca1bcec0c03ce992dec33a45fa\System.Configuration.ni.dll
MOD - [2014/08/20 20:26:11 | 000,223,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\23dd0840f9d45171f3bbd3c45a0a8f9a\System.ServiceProcess.ni.dll
MOD - [2014/08/20 20:26:10 | 010,061,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\42f19eab7abb6a12442e3a9572ad370d\System.ni.dll
MOD - [2014/08/20 20:26:07 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\cf0c209df74c672dfdbd31f9c3e15195\mscorlib.ni.dll
MOD - [2014/07/17 02:40:03 | 000,157,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll
MOD - [2014/05/03 10:16:43 | 000,231,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mswsock.dll
MOD - [2014/05/03 10:16:39 | 001,505,280 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d11.dll
MOD - [2013/11/26 09:16:50 | 003,419,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d2d1.dll
MOD - [2013/10/19 02:36:59 | 000,159,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imagehlp.dll
MOD - [2013/10/12 03:01:25 | 000,216,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\FWPUCLNT.DLL
MOD - [2013/08/13 09:44:22 | 006,912,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
MOD - [2013/08/13 09:44:22 | 001,652,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll
MOD - [2013/08/13 09:44:22 | 000,863,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcr110_clr0400.dll
MOD - [2013/08/13 09:44:22 | 000,788,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNative_v0400.dll
MOD - [2013/08/13 09:44:22 | 000,511,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
MOD - [2013/08/13 09:44:22 | 000,505,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
MOD - [2013/08/13 09:44:22 | 000,108,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsecimpl.dll
MOD - [2013/08/13 09:44:22 | 000,074,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
MOD - [2013/08/13 09:44:22 | 000,042,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\WMINet_Utils.dll
MOD - [2013/07/26 02:55:59 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shdocvw.dll
MOD - [2013/03/29 04:00:44 | 001,080,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10.dll
MOD - [2013/03/29 04:00:44 | 000,293,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dxgi.dll
MOD - [2013/03/29 04:00:44 | 000,220,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d10core.dll
MOD - [2013/03/29 04:00:44 | 000,187,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\UIAnimation.dll
MOD - [2013/03/29 04:00:44 | 000,010,752 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
MOD - [2013/03/29 04:00:44 | 000,009,728 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
MOD - [2013/03/29 04:00:44 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
MOD - [2013/03/29 04:00:44 | 000,005,632 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
MOD - [2013/03/29 04:00:44 | 000,004,096 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
MOD - [2013/03/29 04:00:44 | 000,003,584 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
MOD - [2013/03/29 04:00:44 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
MOD - [2013/03/29 04:00:44 | 000,003,072 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
MOD - [2013/03/29 04:00:44 | 000,002,560 | -H-- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
MOD - [2012/07/04 22:16:56 | 000,057,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netapi32.dll
MOD - [2011/12/16 08:52:58 | 000,690,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcrt.dll
MOD - [2011/11/17 06:35:02 | 000,314,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\webio.dll
MOD - [2011/08/27 05:26:27 | 000,233,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oleacc.dll
MOD - [2011/07/12 09:14:26 | 000,331,776 | R--- | M] (VIA Technologies, Inc.) -- C:\VIA_XHCI\usb3Monitor.exe
MOD - [2011/06/11 01:58:52 | 004,422,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mfc100u.dll
MOD - [2011/06/11 01:58:52 | 000,773,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcr100.dll
MOD - [2011/06/11 01:58:52 | 000,421,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msvcp100.dll
MOD - [2011/06/11 01:58:52 | 000,055,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mfc100enu.dll
MOD - [2011/05/24 11:40:05 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\devobj.dll
MOD - [2011/05/24 11:39:38 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cfgmgr32.dll
MOD - [2011/03/03 06:38:01 | 000,270,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dnsapi.dll
MOD - [2010/11/21 04:25:15 | 000,172,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\spp.dll
MOD - [2010/11/21 04:24:32 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IPHLPAPI.DLL
MOD - [2010/11/21 04:24:26 | 001,128,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vssapi.dll
MOD - [2010/11/21 04:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\fastprox.dll
MOD - [2010/11/21 04:24:25 | 000,119,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\imm32.dll
MOD - [2010/11/21 04:24:23 | 001,828,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d9.dll
MOD - [2010/11/21 04:24:16 | 000,380,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sxs.dll
MOD - [2010/11/21 04:24:16 | 000,269,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\Wldap32.dll
MOD - [2010/11/21 04:24:16 | 000,194,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winmm.dll
MOD - [2010/11/21 04:24:16 | 000,127,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\logoncli.dll
MOD - [2010/11/21 04:24:16 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\srvcli.dll
MOD - [2010/11/21 04:24:16 | 000,081,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\userenv.dll
MOD - [2010/11/21 04:24:16 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\netutils.dll
MOD - [2010/11/21 04:24:14 | 000,295,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\apphelp.dll
MOD - [2010/11/21 04:24:14 | 000,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\RpcRtRemote.dll
MOD - [2010/11/21 04:24:09 | 000,854,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dbghelp.dll
MOD - [2010/11/21 04:24:08 | 000,988,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\propsys.dll
MOD - [2010/11/21 04:24:08 | 000,363,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbemcomn.dll
MOD - [2010/11/21 04:24:08 | 000,351,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winhttp.dll
MOD - [2010/11/21 04:24:08 | 000,320,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winspool.drv
MOD - [2010/11/21 04:24:03 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\olepro32.dll
MOD - [2010/11/21 04:24:01 | 000,297,808 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mscoree.dll
MOD - [2010/11/21 04:24:01 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rtutils.dll
MOD - [2010/11/21 04:23:55 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ws2_32.dll
MOD - [2010/11/21 04:23:54 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\samcli.dll
MOD - [2010/11/21 04:23:54 | 000,040,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wtsapi32.dll
MOD - [2010/11/21 04:23:51 | 001,667,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\setupapi.dll
MOD - [2010/11/21 04:23:51 | 000,213,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\MMDevAPI.dll
MOD - [2010/11/21 04:23:51 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wkscli.dll
MOD - [2010/11/21 04:23:48 | 000,485,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2010/11/21 04:23:48 | 000,350,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\shlwapi.dll
MOD - [2010/11/21 04:23:48 | 000,034,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msasn1.dll
MOD - [2009/08/18 11:29:22 | 000,134,528 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL
MOD - [2009/07/14 02:17:54 | 000,242,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rsaenh.dll
MOD - [2009/07/14 02:16:21 | 000,180,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\xmllite.dll
MOD - [2009/07/14 02:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wsock32.dll
MOD - [2009/07/14 02:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wship6.dll
MOD - [2009/07/14 02:16:20 | 000,009,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WSHTCPIP.DLL
MOD - [2009/07/14 02:16:19 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\wmiutils.dll
MOD - [2009/07/14 02:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winrnr.dll
MOD - [2009/07/14 02:16:19 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winusb.dll
MOD - [2009/07/14 02:16:19 | 000,016,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winnsi.dll
MOD - [2009/07/14 02:16:17 | 000,561,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\UIAutomationCore.dll
MOD - [2009/07/14 02:16:17 | 000,056,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\vsstrace.dll
MOD - [2009/07/14 02:16:17 | 000,047,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\wbemsvc.dll
MOD - [2009/07/14 02:16:17 | 000,029,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\wbemprox.dll
MOD - [2009/07/14 02:16:17 | 000,021,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\version.dll
MOD - [2009/07/14 02:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\sechost.dll
MOD - [2009/07/14 02:16:13 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\SensApi.dll
MOD - [2009/07/14 02:16:12 | 000,791,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\opengl32.dll
MOD - [2009/07/14 02:16:12 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasapi32.dll
MOD - [2009/07/14 02:16:12 | 000,145,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\powrprof.dll
MOD - [2009/07/14 02:16:12 | 000,103,424 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\oledlg.dll
MOD - [2009/07/14 02:16:12 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasman.dll
MOD - [2009/07/14 02:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\pnrpnsp.dll
MOD - [2009/07/14 02:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\profapi.dll
MOD - [2009/07/14 02:16:12 | 000,011,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\rasadhlp.dll
MOD - [2009/07/14 02:16:12 | 000,006,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\psapi.dll
MOD - [2009/07/14 02:16:11 | 000,121,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntmarta.dll
MOD - [2009/07/14 02:16:11 | 000,090,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntdsapi.dll
MOD - [2009/07/14 02:16:11 | 000,008,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\nsi.dll
MOD - [2009/07/14 02:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\NapiNSP.dll
MOD - [2009/07/14 02:15:44 | 000,031,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimtf.dll
MOD - [2009/07/14 02:15:44 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msiltcfg.dll
MOD - [2009/07/14 02:15:44 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msimg32.dll
MOD - [2009/07/14 02:15:43 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msctfui.dll
MOD - [2009/07/14 02:15:40 | 000,177,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mlang.dll
MOD - [2009/07/14 02:15:24 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\hid.dll
MOD - [2009/07/14 02:15:22 | 000,130,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\glu32.dll
MOD - [2009/07/14 02:15:22 | 000,079,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\gpapi.dll
MOD - [2009/07/14 02:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dwmapi.dll
MOD - [2009/07/14 02:15:11 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc.dll
MOD - [2009/07/14 02:15:11 | 000,043,008 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\dhcpcsvc6.dll
MOD - [2009/07/14 02:15:10 | 000,531,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ddraw.dll
MOD - [2009/07/14 02:15:08 | 000,011,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\d3d8thk.dll
MOD - [2009/07/14 02:15:03 | 000,522,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\clbcatq.dll
MOD - [2009/07/14 02:14:57 | 000,070,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\atl.dll
MOD - [2009/07/14 02:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\msscript.ocx
MOD - [2009/07/14 02:11:24 | 000,245,760 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\uxtheme.dll
MOD - [2009/07/14 02:11:20 | 000,080,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\bcrypt.dll
MOD - [2009/07/14 02:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll


========== Services (All) ==========

SRV:64bit: - [2016/05/08 20:24:31 | 000,243,296 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2016/03/31 01:17:56 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2016/03/19 02:42:00 | 000,651,576 | ---- | M] (Apple Inc.) [On_Demand | Running] -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service)
SRV:64bit: - [2016/03/17 23:50:11 | 000,034,816 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appidsvc.dll -- (AppIDSvc)
SRV:64bit: - [2016/03/17 22:35:42 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (VaultSvc)
SRV:64bit: - [2016/03/17 22:35:42 | 000,030,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:64bit: - [2016/03/17 22:35:42 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
SRV:64bit: - [2016/03/17 22:35:42 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (Netlogon)
SRV:64bit: - [2016/03/17 22:35:42 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:64bit: - [2016/03/17 22:35:42 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (EFS)
SRV:64bit: - [2016/03/08 11:07:02 | 006,474,112 | ---- | M] (NVIDIA Corporation) [On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe -- (NvStreamNetworkSvc)
SRV:64bit: - [2016/03/08 11:07:02 | 002,609,024 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe -- (NvStreamSvc)
SRV:64bit: - [2016/03/08 11:07:02 | 001,164,672 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV:64bit: - [2016/03/08 07:27:49 | 001,264,064 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Windows\SysNative\nvvsvc.exe -- (nvsvc)
SRV:64bit: - [2016/03/02 15:31:28 | 000,083,768 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device Service)
SRV:64bit: - [2016/02/12 19:22:06 | 002,610,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:64bit: - [2016/02/09 10:55:34 | 000,030,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:64bit: - [2015/11/10 19:55:29 | 001,180,160 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FntCache.dll -- (FontCache)
SRV:64bit: - [2015/08/12 17:03:42 | 000,462,096 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service)
SRV:64bit: - [2015/08/05 18:56:14 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:64bit: - [2015/07/15 19:10:58 | 001,743,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sysmain.dll -- (SysMain)
SRV:64bit: - [2015/07/01 21:49:56 | 000,260,096 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WebClnt.dll -- (WebClient)
SRV:64bit: - [2015/06/15 22:45:34 | 000,070,656 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:64bit: - [2015/06/15 22:44:47 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV:64bit: - [2015/02/03 04:31:04 | 000,188,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\pcasvc.dll -- (PcaSvc)
SRV:64bit: - [2015/02/03 04:30:56 | 000,187,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV:64bit: - [2015/02/03 04:30:55 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:64bit: - [2015/02/03 04:30:55 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2014/12/19 04:06:55 | 000,210,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:64bit: - [2014/12/06 05:17:27 | 000,303,616 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:64bit: - [2014/10/14 03:13:06 | 000,683,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\termsrv.dll -- (TermService)
SRV:64bit: - [2013/10/12 03:29:21 | 000,859,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\IKEEXT.DLL -- (IKEEXT)
SRV:64bit: - [2013/05/27 06:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/09/25 19:52:54 | 001,255,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV:64bit: - [2012/07/04 23:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:64bit: - [2011/12/09 00:38:24 | 000,607,456 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV:64bit: - [2011/05/24 12:42:55 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:64bit: - [2011/03/03 07:24:16 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:64bit: - [2010/11/21 04:25:14 | 001,504,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbengine.exe -- (wbengine)
SRV:64bit: - [2010/11/21 04:25:14 | 000,689,152 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\FXSSVC.exe -- (Fax)
SRV:64bit: - [2010/11/21 04:25:10 | 000,092,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\TabSvc.dll -- (TabletInputService)
SRV:64bit: - [2010/11/21 04:25:06 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:64bit: - [2010/11/21 04:25:05 | 001,525,248 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV:64bit: - [2010/11/21 04:24:52 | 000,117,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpdbusenum.dll -- (WPDBusEnum)
SRV:64bit: - [2010/11/21 04:24:51 | 000,232,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ListSvc.dll -- (HomeGroupListener)
SRV:64bit: - [2010/11/21 04:24:51 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\provsvc.dll -- (HomeGroupProvider)
SRV:64bit: - [2010/11/21 04:24:48 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:64bit: - [2010/11/21 04:24:42 | 000,084,992 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Mcx2Svc.dll -- (Mcx2Svc)
SRV:64bit: - [2010/11/21 04:24:36 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wcncsvc.dll -- (wcncsvc)
SRV:64bit: - [2010/11/21 04:24:34 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AxInstSv.dll -- (AxInstSV)
SRV:64bit: - [2010/11/21 04:24:33 | 000,121,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SessEnv.dll -- (SessionEnv)
SRV:64bit: - [2010/11/21 04:24:32 | 000,777,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\gpsvc.dll -- (gpsvc)
SRV:64bit: - [2010/11/21 04:24:32 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV:64bit: - [2010/11/21 04:24:32 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)
SRV:64bit: - [2010/11/21 04:24:28 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:64bit: - [2010/11/21 04:24:27 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:64bit: - [2010/11/21 04:24:24 | 002,018,304 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WsmSvc.dll -- (WinRM)
SRV:64bit: - [2010/11/21 04:24:17 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:64bit: - [2010/11/21 04:24:16 | 000,162,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dps.dll -- (DPS)
SRV:64bit: - [2010/11/21 04:24:16 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\KMSVC.DLL -- (hkmsvc)
SRV:64bit: - [2010/11/21 04:24:14 | 000,569,344 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\iphlpsvc.dll -- (iphlpsvc)
SRV:64bit: - [2010/11/21 04:24:09 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:64bit: - [2010/11/21 04:24:09 | 000,080,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\certprop.dll -- (SCPolicySvc)
SRV:64bit: - [2010/11/21 04:24:09 | 000,080,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\certprop.dll -- (CertPropSvc)
SRV:64bit: - [2010/11/21 04:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:64bit: - [2010/11/21 04:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:64bit: - [2010/11/21 04:24:00 | 001,389,056 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pla.dll -- (pla)
SRV:64bit: - [2010/11/21 04:24:00 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:64bit: - [2010/11/21 04:24:00 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV:64bit: - [2010/11/21 04:23:56 | 003,524,608 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\sppsvc.exe -- (sppsvc)
SRV:64bit: - [2010/11/21 04:23:56 | 000,444,416 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\winhttp.dll -- (WinHttpAutoProxySvc)
SRV:64bit: - [2010/11/21 04:23:55 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:64bit: - [2010/11/21 04:23:55 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:64bit: - [2010/11/21 04:23:55 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV:64bit: - [2010/11/21 04:23:51 | 000,849,920 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:64bit: - [2010/11/21 04:23:51 | 000,533,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vds.exe -- (vds)
SRV:64bit: - [2010/11/21 04:23:50 | 000,078,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\WUDFSvc.dll -- (wudfsvc)
SRV:64bit: - [2010/11/21 04:23:48 | 000,501,248 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
SRV:64bit: - [2010/11/21 04:23:48 | 000,476,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\QAGENTRT.DLL -- (napagent)
SRV:64bit: - [2010/11/21 04:23:48 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:64bit: - [2010/04/07 00:30:38 | 000,031,272 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\AppleChargerSrv.exe -- (AppleChargerSrv)
SRV:64bit: - [2010/01/09 21:34:24 | 004,925,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE -- (osppsvc)
SRV:64bit: - [2009/08/18 12:48:02 | 002,291,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV:64bit: - [2009/07/14 02:41:59 | 000,229,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wwansvc.dll -- (WwanSvc)
SRV:64bit: - [2009/07/14 02:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:64bit: - [2009/07/14 02:41:57 | 000,012,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wpcsvc.dll -- (WPCSvc)
SRV:64bit: - [2009/07/14 02:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:64bit: - [2009/07/14 02:41:56 | 000,381,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\w32time.dll -- (W32Time)
SRV:64bit: - [2009/07/14 02:41:56 | 000,353,792 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\upnphost.dll -- (upnphost)
SRV:64bit: - [2009/07/14 02:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:64bit: - [2009/07/14 02:41:56 | 000,237,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wecsvc.dll -- (Wecsvc)
SRV:64bit: - [2009/07/14 02:41:56 | 000,202,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbiosrvc.dll -- (WbioSrvc)
SRV:64bit: - [2009/07/14 02:41:56 | 000,163,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpo.dll -- (Power)
SRV:64bit: - [2009/07/14 02:41:56 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wdi.dll -- (WdiSystemHost)
SRV:64bit: - [2009/07/14 02:41:56 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wdi.dll -- (WdiServiceHost)
SRV:64bit: - [2009/07/14 02:41:56 | 000,084,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wercplsupport.dll -- (wercplsupport)
SRV:64bit: - [2009/07/14 02:41:56 | 000,076,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wersvc.dll -- (WerSvc)
SRV:64bit: - [2009/07/14 02:41:56 | 000,040,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WcsPlugInService.dll -- (WcsPlugInService)
SRV:64bit: - [2009/07/14 02:41:56 | 000,038,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\uxsms.dll -- (UxSms)
SRV:64bit: - [2009/07/14 02:41:55 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\trkwks.dll -- (TrkWks)
SRV:64bit: - [2009/07/14 02:41:55 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tbssvc.dll -- (TBS)
SRV:64bit: - [2009/07/14 02:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:64bit: - [2009/07/14 02:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:64bit: - [2009/07/14 02:41:54 | 000,193,024 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ssdpsrv.dll -- (SSDPSRV)
SRV:64bit: - [2009/07/14 02:41:54 | 000,075,264 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\sstpsvc.dll -- (SstpSvc)
SRV:64bit: - [2009/07/14 02:41:54 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sppuinotify.dll -- (sppuinotify)
SRV:64bit: - [2009/07/14 02:41:54 | 000,029,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sensrsvc.dll -- (SensrSvc)
SRV:64bit: - [2009/07/14 02:41:53 | 000,438,784 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\p2psvc.dll -- (p2psvc)
SRV:64bit: - [2009/07/14 02:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpsvc.dll -- (PNRPsvc)
SRV:64bit: - [2009/07/14 02:41:53 | 000,327,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpsvc.dll -- (p2pimsvc)
SRV:64bit: - [2009/07/14 02:41:53 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\qwave.dll -- (QWAVE)
SRV:64bit: - [2009/07/14 02:41:53 | 000,190,976 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\SCardSvr.dll -- (SCardSvr)
SRV:64bit: - [2009/07/14 02:41:53 | 000,159,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\regsvc.dll -- (RemoteRegistry)
SRV:64bit: - [2009/07/14 02:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:64bit: - [2009/07/14 02:41:53 | 000,067,072 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\RpcEpMap.dll -- (RpcEptMapper)
SRV:64bit: - [2009/07/14 02:41:53 | 000,064,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\Sens.dll -- (SENS)
SRV:64bit: - [2009/07/14 02:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:64bit: - [2009/07/14 02:41:53 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\pnrpauto.dll -- (PNRPAutoReg)
SRV:64bit: - [2009/07/14 02:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV:64bit: - [2009/07/14 02:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:64bit: - [2009/07/14 02:41:28 | 000,368,640 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msdtckrm.dll -- (KtmRm)
SRV:64bit: - [2009/07/14 02:41:27 | 000,097,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\mprdim.dll -- (RemoteAccess)
SRV:64bit: - [2009/07/14 02:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (THREADORDER)
SRV:64bit: - [2009/07/14 02:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:64bit: - [2009/07/14 02:41:18 | 000,300,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lltdsvc.dll -- (lltdsvc)
SRV:64bit: - [2009/07/14 02:41:18 | 000,023,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lmhsvc.dll -- (lmhosts)
SRV:64bit: - [2009/07/14 02:41:11 | 000,156,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\iscsiexe.dll -- (MSiSCSI)
SRV:64bit: - [2009/07/14 02:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:64bit: - [2009/07/14 02:41:09 | 000,101,888 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPBusEnum.dll -- (IPBusEnum)
SRV:64bit: - [2009/07/14 02:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV:64bit: - [2009/07/14 02:40:52 | 000,034,816 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\FDResPub.dll -- (FDResPub)
SRV:64bit: - [2009/07/14 02:40:52 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fdPHost.dll -- (fdPHost)
SRV:64bit: - [2009/07/14 02:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV:64bit: - [2009/07/14 02:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:64bit: - [2009/07/14 02:40:28 | 000,291,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\defragsvc.dll -- (defragsvc)
SRV:64bit: - [2009/07/14 02:40:13 | 000,083,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\bthserv.dll -- (bthserv)
SRV:64bit: - [2009/07/14 02:40:10 | 000,100,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\bdesvc.dll -- (BDESVC)
SRV:64bit: - [2009/07/14 02:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:64bit: - [2009/07/14 02:39:55 | 000,203,264 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wbem\WmiApSrv.exe -- (wmiApSrv)
SRV:64bit: - [2009/07/14 02:39:48 | 000,040,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\UI0Detect.exe -- (UI0Detect)
SRV:64bit: - [2009/07/14 02:39:41 | 000,014,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\snmptrap.exe -- (SNMPTRAP)
SRV:64bit: - [2009/07/14 02:39:37 | 000,593,408 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SearchIndexer.exe -- (WSearch)
SRV:64bit: - [2009/07/14 02:39:21 | 000,141,824 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msdtc.exe -- (MSDTC)
SRV:64bit: - [2009/07/14 02:39:15 | 000,010,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\Locator.exe -- (RpcLocator)
SRV:64bit: - [2009/07/14 02:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dllhost.exe -- (COMSysApp)
SRV:64bit: - [2009/07/14 02:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV - [2016/04/30 01:10:40 | 000,835,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2016/04/19 21:33:06 | 001,362,464 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\BattlEye\BEService.exe -- (BEService)
SRV - [2016/04/08 15:28:05 | 000,269,504 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2016/04/08 03:53:54 | 000,065,176 | ---- | M] (Razer Inc.) [Auto | Running] -- C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe -- (Razer Chroma SDK Service)
SRV - [2016/04/02 18:07:33 | 002,119,688 | ---- | M] (Electronic Arts) [On_Demand | Stopped] -- E:\Origin\OriginClientService.exe -- (Origin Client Service)
SRV - [2016/03/08 11:07:02 | 001,880,960 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2016/03/08 07:15:05 | 000,424,384 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2015/12/14 00:48:02 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2015/11/05 19:19:26 | 000,457,808 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\aunhelper\aunhelper.exe -- (aunhelper)
SRV - [2015/11/05 01:12:06 | 000,188,072 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe -- (Razer Game Scanner Service)
SRV - [2015/08/30 19:47:02 | 000,144,200 | ---- | M] (Google Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdatem)
SRV - [2015/08/30 19:47:02 | 000,144,200 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdate)
SRV - [2015/07/01 21:30:43 | 000,206,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WebClnt.dll -- (WebClient)
SRV - [2015/06/15 22:42:49 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV - [2015/03/22 23:13:42 | 000,076,152 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2015/02/03 04:12:14 | 000,143,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV - [2014/06/30 23:24:49 | 000,859,280 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc)
SRV - [2014/03/20 23:50:31 | 000,090,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2014/03/20 23:49:18 | 000,067,224 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2013/08/13 09:44:22 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/08/13 08:21:26 | 000,124,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_64)
SRV - [2013/08/13 08:21:26 | 000,051,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe -- (aspnet_state)
SRV - [2012/07/13 16:27:00 | 000,769,432 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011/12/16 20:30:40 | 000,363,800 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/12/16 20:30:38 | 000,277,784 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2011/12/16 19:02:56 | 000,161,560 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe -- (jhi_service)
SRV - [2010/11/21 04:25:10 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\provsvc.dll -- (HomeGroupProvider)
SRV - [2010/11/21 04:24:52 | 000,042,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0)
SRV - [2010/11/21 04:24:49 | 000,276,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wcncsvc.dll -- (wcncsvc)
SRV - [2010/11/21 04:24:42 | 000,696,832 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\ehome\ehrecvr.exe -- (ehRecvr)
SRV - [2010/11/21 04:24:32 | 001,175,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WsmSvc.dll -- (WinRM)
SRV - [2010/11/21 04:24:09 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/21 04:24:08 | 001,508,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\pla.dll -- (pla)
SRV - [2010/11/21 04:24:08 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWow64\winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010/11/21 04:24:03 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
SRV - [2010/11/21 04:24:03 | 000,194,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\servicing\TrustedInstaller.exe -- (TrustedInstaller)
SRV - [2010/11/21 04:24:00 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV - [2010/11/21 04:23:55 | 000,113,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\SessEnv.dll -- (SessionEnv)
SRV - [2010/01/21 18:51:12 | 030,963,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/01/09 21:18:00 | 000,149,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)
SRV - [2009/07/14 02:39:09 | 000,127,488 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\ehome\ehsched.exe -- (ehSched)
SRV - [2009/07/14 02:16:20 | 000,010,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\wpcsvc.dll -- (WPCSvc)
SRV - [2009/07/14 02:16:18 | 000,076,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\wdi.dll -- (WdiSystemHost)
SRV - [2009/07/14 02:16:18 | 000,076,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\wdi.dll -- (WdiServiceHost)
SRV - [2009/07/14 02:16:18 | 000,032,768 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\WcsPlugInService.dll -- (WcsPlugInService)
SRV - [2009/07/14 02:16:17 | 000,266,752 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\upnphost.dll -- (upnphost)
SRV - [2009/07/14 02:16:13 | 000,049,664 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\Sens.dll -- (SENS)
SRV - [2009/07/14 02:16:12 | 000,210,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\qwave.dll -- (QWAVE)
SRV - [2009/07/14 02:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV - [2009/07/14 02:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\mprdim.dll -- (RemoteAccess)
SRV - [2009/07/14 02:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV - [2009/07/14 02:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV - [2009/07/14 02:14:35 | 000,428,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWow64\SearchIndexer.exe -- (WSearch)
SRV - [2009/07/14 02:14:28 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\perfhost.exe -- (PerfHost)
SRV - [2009/07/14 02:14:18 | 000,007,168 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\dllhost.exe -- (COMSysApp)
markuk86
Regular Member
 
Posts: 15
Joined: May 7th, 2016, 5:32 am
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 173 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware