Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.03.2019Ran by gaming (administrator) on LAPTOP-RD8OALJ1 (12-04-2019 14:29:40)Running from C:\Users\gaming\DownloadsLoaded Profiles: gaming (Available Profiles: defaultuser0 & Yaokeroa & louis & gaming)Platform: Windows 10 Home Single Language Version 1803 17134.523 (X64) Language: English (United States)Default browser: "C:\Program Files (x86)\Comodo\Dragon\dragon.exe" -- "%1"Boot Mode: NormalTutorial for Farbar Recovery Scan Tool: -frst-tutorial-how-to-use-farbar-recovery-scan-tool/==================== Processes (Whitelisted) =================(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)(Garena Online Pte Ltd -> Garena Online ) C:\Program Files (x86)\Garena\Garena\2.0.1902.0110\gxxsvc.exe(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\Locator.exe(Comodo Security Solutions, Inc. -> COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe(Comodo Security Solutions, Inc. -> COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe(Comodo Security Solutions, Inc. -> COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe(HP Inc. -> HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe(Comodo Security Solutions, Inc. -> COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe(Microsoft Windows -> Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe(Microsoft Corporation -> Sysinternals - www.sysinternals.com) C:\Users\gaming\Desktop\PROCEXP.exe(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe(Comodo Security Solutions, Inc. -> COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe(Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe==================== Registry (Whitelisted) ===========================(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows -> Microsoft Corporation)HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3665872 2018-01-29] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [231640 2016-09-21] (Realtek Semiconductor Corp -> Realtek Semiconductor Corporation)HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2670056 2018-09-10] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)HKLM\...\Run: [COMODO Autostart D5EFF3B3-E126-4AF6-BCE9-852A72129E10] => C:\Program Files\COMODO\COMODO Internet Security\cis.exe [13064896 2019-03-22] (Comodo Security Solutions, Inc. -> COMODO)HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [705784 2016-06-21] (HP Inc. -> HP Inc.)HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2409944 2018-06-22] (Adobe Systems Incorporated -> Adobe Systems Incorporated)HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694080 2013-04-01] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2133728 2017-09-12] (Wondershare Technology Co.,Ltd -> Wondershare)HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [98024 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)HKLM-x32\...\Run: [IseUI] => C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exeHKLM\ DisallowedCertificates: 03D22C9C66915D58C88912B64C1F984B8344EF09 (Comodo Security Solutions) C:\rewis\Apps\Rainmeter\Rainmeter.exe (Firebit OU -> Rainmeter)Startup: C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2019-04-08]ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\louis\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook, Inc. -> Facebook)Startup: C:\Users\Yaokeroa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP DeskJet 5810 series.lnk [2018-06-22]ShortcutTarget: Monitor Ink Alerts - HP DeskJet 5810 series.lnk -> C:\Program Files\HP\HP DeskJet 5810 series\Bin\HPStatusBL.dll (Hewlett Packard -> Hewlett-Packard Development Company, LP)CHR HKLM\SOFTWARE\Policies\Google: Restriction DefaultScope 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_softjug_18_13_ssg0514¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dph%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutA0EzyyDtDzy0E0D0ByBzzzy0C0AyE0BtN0D0Tzu0StBtByBzztN1L2XzuyEtFtByEtFtDtFyCyCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAtDyCtDtAyDtByCtGyByC0EyBtG0AyD0B0BtGyE0FyEyEtGyDyC0ByEtB0A0ByByEyBzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S1QyCtC1SyDtC1Q1QtGyC1SyCtAtGyEyD1OyBtGzyzyzzyDtGzy1P1OzzyE1P1SzyyD1OtDtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyCyEtByBtN1Q2Z1B1P1RzutCyDtBtBtByEyEzzyDyE%26cr%3D1063928213%26a%3Dwbf_softjug_18_13_ssg0514%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage&p=searchTermsSearchScopes: HKLM -> 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_softjug_18_13_ssg0514¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dph%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutA0EzyyDtDzy0E0D0ByBzzzy0C0AyE0BtN0D0Tzu0StBtByBzztN1L2XzuyEtFtByEtFtDtFyCyCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAtDyCtDtAyDtByCtGyByC0EyBtG0AyD0B0BtGyE0FyEyEtGyDyC0ByEtB0A0ByByEyBzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S1QyCtC1SyDtC1Q1QtGyC1SyCtAtGyEyD1OyBtGzyzyzzyDtGzy1P1OzzyE1P1SzyyD1OtDtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyCyEtByBtN1Q2Z1B1P1RzutCyDtBtBtByEyEzzyDyE%26cr%3D1063928213%26a%3Dwbf_softjug_18_13_ssg0514%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage&p=searchTermsSearchScopes: HKLM-x32 -> DefaultScope ielnksrch URL =SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGkzD5pDvVJeyNgjks8VJWt1cG1TNK6LsXAMvN9gBInFSyFks-vHO08iJOqpENsPWRij67NVz33aZlxkjq1oVxNvwJGvUKem_Pq8HP1lN_qyav9tPkW3oW4mfNNEf-q2dkhaqLESXJPSvFc-wGn30FOEm1AOZyeRZ2I9coyYP7Nb&q=searchTermsSearchScopes: HKLM-x32 -> 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_softjug_18_13_ssg0514¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dph%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutA0EzyyDtDzy0E0D0ByBzzzy0C0AyE0BtN0D0Tzu0StBtByBzztN1L2XzuyEtFtByEtFtDtFyCyCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAtDyCtDtAyDtByCtGyByC0EyBtG0AyD0B0BtGyE0FyEyEtGyDyC0ByEtB0A0ByByEyBzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S1QyCtC1SyDtC1Q1QtGyC1SyCtAtGyEyD1OyBtGzyzyzzyDtGzy1P1OzzyE1P1SzyyD1OtDtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyCyEtByBtN1Q2Z1B1P1RzutCyDtBtBtByEyEzzyDyE%26cr%3D1063928213%26a%3Dwbf_softjug_18_13_ssg0514%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage&p=searchTermsSearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1003 -> DefaultScope ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKA1VtC1mRJr0-ErUX9LRVRJoPYFrh23LfWS_NUPcNkJhFlB9XEC_AEilFYLBtYLuthiSUbc6DeTIYVrjb-BWVVAMAJG8trf0DuVSXmXOyCoOHOR7oxsx7ZEhoeHYsUSKqw_eKYj6cZ0rg-Iv6B87G1qA7PRgIF0_Ll_SjO1UzNnBKZlEc8TUyc7&q=searchTermsSearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1003 -> 0633EE93-D776-472f-A0FF-E1416B8B2E3A URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_softjug_18_13_ssg0514¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dph%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1QzutA0EzyyDtDzy0E0D0ByBzzzy0C0AyE0BtN0D0Tzu0StBtByBzztN1L2XzuyEtFtByEtFtDtFyCyCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StAtDyCtDtAyDtByCtGyByC0EyBtG0AyD0B0BtGyE0FyEyEtGyDyC0ByEtB0A0ByByEyBzz0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S1QyCtC1SyDtC1Q1QtGyC1SyCtAtGyEyD1OyBtGzyzyzzyDtGzy1P1OzzyE1P1SzyyD1OtDtA2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCyCyEtByBtN1Q2Z1B1P1RzutCyDtBtBtByEyEzzyDyE%26cr%3D1063928213%26a%3Dwbf_softjug_18_13_ssg0514%26os_ver%3D10.0%26os%3DWindows%2B10%2BHome%2BSingle%2BLanguage&p=searchTermsSearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1003 -> 2f23ab71-4ac6-41f2-a955-ea576e553146 URL =SearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1003 -> BDF61FAE-9D19-40F0-8F34-688DEB334CA9 URL = hxxp://securedsearch.lavasoft.com/results.php?pr=vmn&id=webcompa&ent=ch_WCYID10454__180811&q=searchTermsSearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1003 -> E1CA3C1E-284F-4558-A218-35B521DAE198 URL = hxxp://www.bing.com/search?FORM=WLETDF&PC=WLEM&q=searchTerms&src=IE-SearchBoxSearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1003 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKA1VtC1mRJr0-ErUX9LRVRJoPYFrh23LfWS_NUPcNkJhFlB9XEC_AEilFYLBtYLuthiSUbc6DeTIYVrjb-BWVVAMAJG8trf0DuVSXmXOyCoOHOR7oxsx7ZEhoeHYsUSKqw_eKYj6cZ0rg-Iv6B87G1qA7PRgIF0_Ll_SjO1UzNnBKZlEc8TUyc7&q=searchTermsSearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1009 -> DefaultScope 0AA24E16-07B3-4694-8357-3C21ACC5F516 URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=comodo&hsimp=yhs-com_chrome&type=33010001005_12.0.0.6810_i_ds_sp&p=searchTermsSearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1009 -> 0AA24E16-07B3-4694-8357-3C21ACC5F516 URL = hxxps://ph.search.yahoo.com/yhs/search?hspart=comodo&hsimp=yhs-com_chrome&type=33010001005_12.0.0.6810_i_ds_sp&p=searchTermsSearchScopes: HKU\S-1-5-21-3470749901-1448784153-1402439068-1009 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoGkzD5pDvVJeyNgjks8VJWt1cG1TNK6LsXAMvN9gBInFSyFks-vHO08iJOqpENsPWRij67NVz33aZlxkjq1oVxNvwJGvUKem_Pq8HP1lN_qyav9tPkW3oW4mfNNEf-q2dkhaqLESXJPSvFc-wGn30FOEm1AOZyeRZ2I9coyYP7Nb&q=searchTermsBHO: IDM integration (IDMIEHlprObj Class) -> 0055C089-8582-441B-A0BF-17B458C2A3A8 -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2018-11-21] (Tonec Inc. -> Internet Download Manager, Tonec Inc.)BHO: ExplorerWnd Helper -> 10921475-03CE-4E04-90CE-E2E7EF20C814 -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2018-07-19] (IObit Information Technology -> IObit)BHO: Java™ Plug-In SSV Helper -> 761497BB-D6F0-462C-B6EB-D4DAF1D92D43 -> C:\Program Files\Java\jre1.8.0_181\bin\ssv.dll [2019-04-02] (Oracle America, Inc. -> Oracle Corporation)BHO: Java™ Plug-In 2 SSV Helper -> DBC80044-A445-435b-BC74-9C25C1C588A9 -> C:\Program Files\Java\jre1.8.0_181\bin\jp2ssv.dll [2019-04-02] (Oracle America, Inc. -> Oracle Corporation)BHO: HP Network Check Helper -> E76FD755-C1BA-4DCB-9F13-99BD91223ADE -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-12-07] (HP Inc. -> HP Inc.)BHO-x32: IDM integration (IDMIEHlprObj Class) -> 0055C089-8582-441B-A0BF-17B458C2A3A8 -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2018-11-21] (Tonec Inc. -> Internet Download Manager, Tonec Inc.)BHO-x32: FlashGetBHO -> b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0 -> C:\Users\123\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll [2012-11-01] (Trend Media Corporation Limited -> Trend Media Group)BHO-x32: HP Network Check Helper -> E76FD755-C1BA-4DCB-9F13-99BD91223ADE -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-12-07] (HP Inc. -> HP Inc.)Handler: ms-help - 314111c7-a502-11d2-bbca-00c04f8ec294 - No FileHandler: mso-minsb-roaming.16 - No CLSID ValueHandler: osf-roaming.16 - No CLSID ValueFilter: text/xml - No CLSID ValueFireFox:========FF DefaultProfile: fuytv3cg.defaultFF ProfilePath: C:\Users\gaming\AppData\Roaming\Mozilla\Firefox\Profiles\fuytv3cg.default [2019-04-12]FF SearchPlugin: C:\Users\gaming\AppData\Roaming\Mozilla\Firefox\Profiles\fuytv3cg.default\searchplugins\AdTrustMediaSafeSearch.xml [2019-04-08]FF HKU\S-1-5-21-3470749901-1448784153-1402439068-1003\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\123\AppData\Roaming\IDM\idmmzcc5 => not foundFF HKU\S-1-5-21-3470749901-1448784153-1402439068-1003\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpiFF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-12-20] [Legacy]FF HKU\S-1-5-21-3470749901-1448784153-1402439068-1009\...\Firefox\Extensions: [mozilla_cc3@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpiFF Extension: (IDM Integration Module) - C:\Program Files (x86)\Internet Download Manager\idmmzcc3.xpi [2019-03-19] [UpdateUrl:hxxps://data.internetdownloadmanager.com/idmmzcc3/update.json]FF HKU\S-1-5-21-3470749901-1448784153-1402439068-1009\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\gaming\AppData\Roaming\IDM\idmmzcc5FF Extension: (IDM CC) - C:\Users\gaming\AppData\Roaming\IDM\idmmzcc5 [2019-04-08] [Legacy] [not signed]FF HKU\S-1-5-21-3470749901-1448784153-1402439068-1009\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpiFF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_156.dll [2019-03-22] (Adobe Systems Incorporated -> )FF Plugin: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2019-04-02] (Oracle America, Inc. -> Oracle Corporation)FF Plugin: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2019-04-02] (Oracle America, Inc. -> Oracle Corporation)FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [No File]FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_156.dll [2019-03-22] (Adobe Systems Incorporated -> )FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\TXE Components\IPT\npIntelWebAPIIPT.dll [2014-07-02] (Intel Identity Protection Technology Software -> Intel Corporation)FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\TXE Components\IPT\npIntelWebAPIUpdater.dll [2014-07-02] (Intel Identity Protection Technology Software -> Intel Corporation)FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA2\MICROS2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation -> Microsoft Corporation)FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [No File]Chrome:=======CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2019-03-21]CHR HKLM\...\Chrome\Extension: [pdpcpceofkopegffcdnffeenbfdldock] - hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crxCHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2019-03-21]CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx==================== Services (Whitelisted) ====================(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818128 2018-06-22] (Adobe Systems Incorporated -> Adobe Systems Incorporated)S4 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2910696 2018-09-10] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)S4 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2704872 2018-09-10] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)S3 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [466280 2019-03-20] (Avira Operations GmbH & Co. KG -> Avira Operations GmbH & Co. KG)S4 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [126944 2017-03-08] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corp.)R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [11398752 2019-03-22] (Comodo Security Solutions, Inc. -> COMODO)R2 CmdAgentProt; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [11398752 2019-03-22] (Comodo Security Solutions, Inc. -> COMODO)S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2651840 2019-03-26] (Comodo Security Solutions, Inc. -> COMODO)S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-09-10] (Dropbox, Inc -> Dropbox, Inc.)S4 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-09-10] (Dropbox, Inc -> Dropbox, Inc.)S4 EsgShKernel; C:\Program Files\EnigmaSoft\SpyHunter\ShKernel.exe [10191664 2019-02-22] (EnigmaSoft Limited -> EnigmaSoft Limited)S4 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [1701480 2018-01-29] (Intel Corporation -> Intel Corporation)S4 ETDService; C:\Program Files\Elantech\ETDService.exe [153040 2018-01-29] (ELAN Microelectronics Corporation -> ELAN Microelectronics Corp.)R2 GarenaPlatform; C:\Program Files (x86)\Garena\Garena\2.0.1902.0110\gxxsvc.exe [320512 2019-02-01] (Garena Online Pte Ltd -> Garena Online )S4 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1194512 2018-06-06] (Garmin International, Inc. -> Garmin Ltd. or its subsidiaries)S4 HP Comm Recover; C:\Program Files\HPCommRecovery\HPCommRecovery.exe [1309184 2016-10-08] (HP Inc.) [File not signed]S4 HP Orbit Service; C:\Program Files\HP\HP Orbit Service\HPOrbitService.exe [3421616 2017-06-20] (HP Inc. -> HP Inc.)S4 HPJumpStartBridge; C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe [471040 2017-05-23] (HP Inc. -> HP Inc.)S4 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-04] (Hewlett-Packard Company -> HP)R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [347512 2018-12-06] (HP Inc. -> HP Inc.)S4 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [631800 2016-06-21] (HP Inc. -> HP Inc.)S4 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [356336 2017-02-02] (Intel pGFX -> Intel Corporation)S4 Intel Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [887784 2015-09-04] (Intel Trusted Connect Service -> Intel Corporation)S4 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [153360 2018-09-25] (IObit Information Technology -> IObit)S4 jhi_service; C:\Program Files (x86)\Intel\TXE Components\DAL\jhi_service.exe [174368 2015-04-22] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)S4 pgt_svc; C:\Program Files (x86)\ProxyGate\MainService.exe [2285664 2017-02-22] (GOLD CLICK LIMITED -> Gold Click Ltd) )S4 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [253776 2018-04-06] (Razer USA Ltd. -> Razer Inc)S4 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [534400 2018-07-28] (Razer USA Ltd. -> Razer Inc.)S4 ShMonitor; C:\Program Files\EnigmaSoft\SpyHunter\ShMonitor.exe [539440 2019-02-22] (EnigmaSoft Limited -> EnigmaSoft Limited)S2 TermService; C:\WINDOWS\System32\svchost.exe [51288 2018-04-12] (Microsoft Windows Publisher -> Microsoft Corporation) Microsoft Corporation) Wellbia.com Co., Ltd.)S4 uSHAREitSvc; C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2017-09-11] (SHAREit Technologies Co.Ltd -> SHAREit Technologies Co.Ltd)S4 Virtual Router; C:\Program Files (x86)\Virtual Router\VirtualRouterService.exe [12288 2013-02-10] (Chris Pietschmann (hxxp://pietschsoft.com)) [File not signed]S4 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2013-04-22] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)S4 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270192 2013-04-01] (Western Digital Technologies, Inc. -> Western Digital Technologies, Inc.)S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4451616 2018-04-12] (Microsoft Corporation -> Microsoft Corporation)S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [107136 2018-09-21] (Microsoft Corporation -> Microsoft Corporation)S4 ZPN Connect; C:\Users\123\AppData\Local\ZPN Connect\ZpnSrv.exe [222720 2015-11-22] () [File not signed]S2 AdobeARMservice; no ImagePathS2 DragonUpdater; "C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe" [X]S2 isesrv; "C:\Program Files (x86)\COMODO\Internet Security Essentials\isesrv.exe" -service [X]S2 Quoteex; no ImagePath Bluestack System Inc. )S0 cmdboot; C:\WINDOWS\System32\DRIVERS\cmdboot.sys [17872 2019-03-18] (Microsoft Windows Early Launch Anti-malware Publisher -> COMODO)R1 cmderd; C:\WINDOWS\System32\DRIVERS\cmderd.sys [43416 2019-03-18] (Comodo Security Solutions, Inc. -> COMODO)R1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [849048 2019-03-18] (Comodo Security Solutions, Inc. -> COMODO)S3 DFX11_1; C:\WINDOWS\system32\drivers\dfx11_1x64.sys [28008 2012-12-13] (Power Technology -> Windows Win 7 DDK provider)S3 DFX12; C:\WINDOWS\system32\drivers\dfx12x64.sys [37704 2015-10-14] (Power Technology -> Windows Win 7 DDK provider)S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-11-23] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [74168 2018-01-29] (Intel Corporation -> Intel Corporation)R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [69560 2018-01-29] (Intel Corporation -> Intel Corporation)R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [382392 2018-01-29] (Intel Corporation -> Intel Corporation)R3 ETDSMBus; C:\WINDOWS\System32\drivers\ETDSMBus.sys [32840 2017-02-14] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronic Corp.)R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-10-24] (Martin Malik - REALiX -> REALiX™)R3 igfxLP; C:\WINDOWS\system32\DRIVERS\igdkmd64lp.sys [7407072 2017-02-02] (Intel pGFX -> Intel Corporation)R1 isedrv; C:\WINDOWS\system32\drivers\isedrv.sys [63256 2018-08-30] (Comodo Security Solutions, Inc. -> COMODO)R1 ISODrive; C:\rewis\Game\UltraISO\drivers\ISODrv64.sys [115448 2013-11-21] (SHENZHEN YIBO DIGITAL SYSTEMS DEVELOPMENT CO. LTD. -> EZB Systems, Inc.)S3 IUProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys [37184 2018-10-16] (IObit Information Technology -> IObit)S3 IURegistryFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys [43392 2018-10-16] (IObit Information Technology -> IObit)R2 npf; C:\WINDOWS\System32\drivers\npf.sys [36600 2014-08-19] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)S3 ProtonVPNSplitTunnelCalloutDriver; C:\Program Files (x86)\Proton Technologies\ProtonVPN\Resources\64-bit\win10\ProtonVPNSplitTunnelCalloutDriver.Sys [48664 2018-10-04] (Microsoft Windows Hardware Compatibility Publisher -> )R0 pwdrvio; C:\WINDOWS\System32\pwdrvio.sys [19152 2013-09-30] (MiniTool Solution Ltd -> )S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] (MiniTool Solution Ltd -> )S3 qcusbnet; C:\WINDOWS\System32\drivers\qcusbnet.sys [428600 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)S3 qcusbser; C:\WINDOWS\system32\DRIVERS\qcusbser.sys [254520 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1024848 2018-02-05] (Realtek Semiconductor Corp. -> Realtek )R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [784264 2018-05-31] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation)R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [7904088 2018-04-20] (Realtek Semiconductor Corp. -> Realtek Semiconductor Corporation )R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit Information Technology -> IObit)S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2018-03-02] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)S3 ssudserd; C:\WINDOWS\system32\DRIVERS\ssudserd.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)R3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [40664 2015-02-03] (OpenVPN Technologies, Inc. -> The OpenVPN Project)R3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [44976 2018-06-01] (Microsoft Windows Hardware Compatibility Publisher -> The OpenVPN Project)R3 TXEIx64; C:\WINDOWS\System32\drivers\TXEIx64.sys [146200 2015-10-15] (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation)R3 USBPcap; C:\WINDOWS\system32\DRIVERS\USBPcap.sys [50224 2017-08-21] (Tomasz Moń -> USBPcap)S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44616 2018-04-12] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [331680 2018-04-12] (Microsoft Windows -> Microsoft Corporation)S3 wdm_usb; C:\WINDOWS\system32\DRIVERS\usb2ser.sys [151184 2018-03-02] (NGO -> MBB)S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [44032 2018-04-12] (Microsoft Windows -> Microsoft Corporation)R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [35568 2018-08-31] (HP Inc. -> HP)S3 xhunter1; C:\WINDOWS\xhunter1.sys [74552 2019-03-10] (Wellbia.com Co., Ltd. -> Wellbia.com Co., Ltd.)R1 YSDrv; C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys [310536 2019-03-26] (Beijing Duodian Online Science and Technology Co.,Ltd -> BigNox Corporation)S3 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X]S4 IUFileFilter; \??\C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys [X]S1 ujjnroer; \??\C:\WINDOWS\system32\drivers\ujjnroer.sys [X]==================== NetSvcs (Whitelisted) ===================(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)==================== One month (created) ========(If an entry is included in the fixlist, the file/folder will be moved.)2019-04-12 14:29 - 2019-04-12 14:33 - 000042388 _____ C:\Users\gaming\Downloads\FRST.txt2019-04-12 14:29 - 2019-04-12 14:29 - 000000000 ____D C:\FRST2019-04-12 14:27 - 2019-04-12 14:27 - 002434048 _____ (Farbar) C:\Users\gaming\Downloads\FRST64.exe2019-04-12 13:55 - 2019-04-12 13:55 - 000003484 _____ C:\WINDOWS\System32\Tasks\gxx speed launcher2019-04-11 18:45 - 2019-04-11 23:51 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update2019-04-09 21:36 - 2018-11-17 07:22 - 001449008 _____ (Sysinternals - www.sysinternals.com) C:\Users\gaming\Desktop\PROCEXP.exe2019-04-09 21:16 - 2019-04-09 21:16 - 000003306 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v22019-04-09 01:19 - 2019-04-09 01:19 - 000000000 ____D C:\Users\gaming\AppData\Local\Hewlett-Packard2019-04-09 00:08 - 2019-04-09 00:08 - 000000000 ____D C:\Users\gaming\AppData\Local\4kdownload.com2019-04-09 00:07 - 2019-04-09 00:07 - 000000936 _____ C:\Users\gaming\Desktop\4K Video Downloader.lnk2019-04-09 00:07 - 2019-04-09 00:07 - 000000000 ____D C:\Program Files\4KDownload2019-04-09 00:06 - 2019-04-09 00:06 - 000000000 ____D C:\Users\gaming\AppData\Roaming\MPC-HC2019-04-09 00:01 - 2019-04-09 00:02 - 025321472 _____ C:\Users\gaming\Downloads\4kvideodownloader_4.7.0_x64.msi2019-04-08 23:53 - 2019-04-09 12:55 - 000000000 ____D C:\Users\gaming\AppData\Roaming\DMCache2019-04-08 23:53 - 2019-04-09 01:12 - 000000368 _____ C:\WINDOWS\Tasks\HPCeeScheduleForgaming.job2019-04-08 23:53 - 2019-04-08 23:55 - 000000000 ____D C:\Users\gaming\AppData\Roaming\IDM2019-04-08 23:53 - 2019-04-08 23:53 - 000003264 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForgaming2019-04-08 23:53 - 2019-04-08 23:53 - 000000000 ____D C:\Users\gaming\Downloads\Video2019-04-08 23:53 - 2019-04-08 23:53 - 000000000 ____D C:\Users\gaming\Downloads\Compressed2019-04-08 23:53 - 2019-04-08 23:53 - 000000000 ____D C:\Users\gaming\AppData\Local\HP_Development_Company,_L2019-04-08 23:50 - 2019-04-09 01:19 - 000000000 ____D C:\Users\gaming\AppData\Roaming\hpqLog2019-04-08 18:15 - 2019-04-08 18:15 - 000000000 ____D C:\Users\Yaokeroa\AppData\LocalLow\Mozilla2019-04-08 18:14 - 2019-04-08 18:14 - 000000000 ____D C:\Users\Yaokeroa\AppData\Local\Mozilla2019-04-08 18:06 - 2019-04-08 18:06 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job2019-04-08 17:09 - 2019-04-08 17:09 - 000000000 ___HD C:\VTRoot2019-04-08 17:03 - 2019-04-08 17:03 - 000000000 ____D C:\Users\gaming\AppData\Local\File Viewer Plus 32019-04-08 17:00 - 2019-04-08 17:00 - 000000000 ____D C:\Users\gaming\AppData\Local\Sharpened_Productions2019-04-08 15:12 - 2019-04-11 00:47 - 000065214 _____ C:\WINDOWS\system32\Drivers\fvstore.dat2019-04-08 15:08 - 2019-04-12 14:34 - 001474832 _____ C:\WINDOWS\system32\Drivers\sfi.dat2019-04-08 15:08 - 2019-04-08 15:08 - 000002161 _____ C:\Users\Public\Desktop\COMODO Antivirus.lnk2019-04-08 15:08 - 2019-04-08 15:08 - 000000000 ____D C:\WINDOWS\System32\Tasks\COMODO2019-04-08 15:08 - 2019-03-18 20:22 - 000017872 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmdboot.sys2019-04-08 15:07 - 2019-04-08 15:07 - 000000000 ____D C:\Program Files\COMODO2019-04-08 15:05 - 2019-04-08 15:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo2019-04-08 15:05 - 2019-04-08 15:05 - 000002192 _____ C:\Users\Public\Desktop\Comodo Dragon.lnk2019-04-08 15:05 - 2019-04-08 15:05 - 000000000 ____D C:\Users\gaming\AppData\Local\Comodo2019-04-08 15:05 - 2019-01-29 16:42 - 000254440 _____ (COMODO) C:\WINDOWS\system32\iseguard64.dll2019-04-08 15:05 - 2019-01-29 16:42 - 000205024 _____ (COMODO) C:\WINDOWS\SysWOW64\iseguard32.dll2019-04-08 15:05 - 2018-08-30 06:55 - 000063256 _____ (COMODO) C:\WINDOWS\system32\Drivers\isedrv.sys2019-04-08 14:37 - 2019-04-08 14:37 - 000000571 _____ C:\Users\gaming\Desktop\Nhs High.txt2019-04-08 11:56 - 2019-04-08 11:56 - 000000000 ____D C:\Users\gaming\AppData\Roaming\Hewlett-Packard2019-04-08 11:51 - 2019-04-08 11:51 - 000000258 __RSH C:\Users\gaming\ntuser.pol2019-04-07 23:12 - 2019-04-07 23:15 - 000000000 ____D C:\ProgramData\Comodo Downloader2019-04-07 23:12 - 2019-04-07 23:12 - 000000000 ____D C:\ProgramData\Shared Space2019-04-07 23:11 - 2019-04-07 23:11 - 005625008 ____N (COMODO) C:\Users\gaming\Downloads\cav_installer_10309_3f.exe2019-04-07 02:16 - 2019-04-07 02:44 - 000000000 ____D C:\Users\louis\Downloads\Video2019-04-07 01:34 - 2019-04-07 01:52 - 000000000 ____D C:\Users\louis\AppData\Roaming\Televzr Desktop2019-04-07 01:34 - 2019-04-07 01:37 - 000000000 ____D C:\Users\louis\Downloads\Televzr Downloads2019-04-07 01:34 - 2019-04-07 01:34 - 000000000 ____D C:\Users\louis\AppData\Roaming\Televzr2019-04-07 01:33 - 2019-04-08 16:54 - 000000000 ____D C:\Users\louis\AppData\Local\Televzr2019-04-07 01:33 - 2019-04-07 01:33 - 000001138 _____ C:\Users\Public\Desktop\Televzr.lnk2019-04-07 01:33 - 2019-04-07 01:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Televzr2019-04-06 22:44 - 2019-04-06 22:48 - 000000112 _____ C:\Users\louis\Desktop\gewfdx.vbs2019-04-06 14:09 - 2018-11-17 07:22 - 001449008 _____ (Sysinternals - www.sysinternals.com) C:\Users\louis\Downloads\procexp64.exe2019-04-06 14:09 - 2018-11-17 07:22 - 000072154 _____ C:\Users\louis\Downloads\procexp.chm2019-04-06 14:06 - 2019-04-06 14:07 - 001828569 _____ C:\Users\louis\Downloads\ProcessExplorer.zip2019-04-05 16:38 - 2019-04-05 16:38 - 000001276 _____ C:\Users\Public\Desktop\Avira.lnk2019-04-05 16:38 - 2019-04-05 16:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira2019-04-05 16:38 - 2019-04-05 16:38 - 000000000 ____D C:\ProgramData\Avira2019-04-05 16:38 - 2019-04-05 16:38 - 000000000 ____D C:\Program Files (x86)\Avira2019-04-05 15:33 - 2019-04-05 15:33 - 000000000 ____D C:\Users\louis\AppData\Local\Sharpened_Productions2019-04-05 15:33 - 2019-04-05 15:33 - 000000000 ____D C:\Users\louis\AppData\Local\File Viewer Plus 32019-04-05 15:31 - 2019-04-10 18:37 - 000000000 ____D C:\Program Files (x86)\File Identifier2019-04-05 15:31 - 2019-04-05 15:31 - 000001143 _____ C:\Users\Public\Desktop\File Viewer Plus 3.lnk2019-04-05 15:31 - 2019-04-05 15:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Viewer Plus 32019-04-05 15:31 - 2019-04-05 15:31 - 000000000 ____D C:\Program Files (x86)\File Viewer Plus 32019-04-05 15:24 - 2019-04-05 15:28 - 085300888 _____ (Sharpened Productions ) C:\Users\louis\Downloads\fvp_setup_3.1.1.25fi.exe2019-04-05 15:12 - 2019-04-09 21:09 - 000000000 ____D C:\WINDOWS\AppReadiness2019-04-05 14:48 - 2019-04-05 14:48 - 000021436 _____ C:\Users\louis\Downloads\CheatMod-master.zip2019-04-05 13:20 - 2019-04-05 13:21 - 000077119 _____ C:\Users\louis\Downloads\35286864_percentager.zip2019-04-05 12:22 - 2019-04-05 12:23 - 005507072 _____ C:\Users\louis\Downloads\full-tweakbit-anti-malware-221-crack-cracksnow_0add5cb-2801.iso2019-04-05 12:01 - 2019-04-05 12:04 - 007719749 _____ C:\Users\louis\Downloads\TweakBit.Anti-Malware.2.2.1.3_Startcrack.com.rar2019-04-05 11:38 - 2019-04-05 11:38 - 000000000 ____D C:\Users\louis\Downloads\Compressed2019-04-05 11:20 - 2019-04-05 12:04 - 000000000 ____D C:\ProgramData\TweakBit2019-04-05 11:20 - 2019-04-05 11:20 - 000001262 _____ C:\Users\louis\Desktop\TweakBit PCRepairKit.lnk2019-04-05 11:20 - 2019-04-05 11:20 - 000000000 ____D C:\WINDOWS\System32\Tasks\TweakBit2019-04-05 11:20 - 2019-04-05 11:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TweakBit2019-04-05 11:20 - 2019-04-05 11:20 - 000000000 ____D C:\Program Files (x86)\TweakBit2019-04-05 11:17 - 2019-04-05 11:17 - 000000000 _____ C:\Users\louis\Downloads\clamwin-0.99.4-setup.exe2019-04-05 11:16 - 2019-04-05 11:21 - 118075392 _____ (alch ) C:\Users\louis\Downloads\clamwin-0.99.4-setup.exe.part2019-04-05 09:36 - 2019-04-05 09:36 - 000000000 _____ C:\Users\louis\Desktop\0x810000204.txt2019-04-04 19:58 - 2019-04-07 15:55 - 000000000 ____D C:\Users\louis\Downloads\opera autoupdate2019-04-04 19:44 - 2010-03-18 21:36 - 005522768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc100u.dll2019-04-04 19:44 - 2010-03-18 21:36 - 005493576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc100.dll2019-04-04 19:44 - 2010-03-18 21:36 - 000607568 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp100.dll2019-04-04 19:38 - 2019-04-04 19:38 - 006778600 _____ C:\Users\gaming\Downloads\0xc000007b_win10(x64).zip2019-04-04 19:22 - 2019-04-04 19:22 - 001075827 _____ C:\Users\gaming\Downloads\qt5v8.zip2019-04-04 19:14 - 2019-04-04 19:15 - 000516225 _____ C:\Users\gaming\Downloads\libglesv2.zip2019-04-04 19:09 - 2016-10-12 09:09 - 000001983 _____ C:\Users\gaming\Downloads\README.txt2019-04-04 19:05 - 2019-04-04 19:05 - 000725259 _____ C:\Users\gaming\Downloads\qt5quick.zip2019-04-04 18:38 - 2019-04-04 18:38 - 000003722 _____ C:\WINDOWS\System32\Tasks\snp2019-04-04 18:38 - 2019-04-04 18:38 - 000003304 _____ C:\WINDOWS\System32\Tasks\snf2019-04-04 18:37 - 2019-04-04 18:38 - 000015606 _____ C:\WINDOWS\SysWOW64\findit.xml2019-04-04 18:37 - 2019-04-04 18:37 - 000722944 _____ C:\Users\gaming\AppData\Local\sha.db2019-04-04 18:37 - 2019-04-04 18:37 - 000140800 _____ C:\Users\gaming\AppData\Local\installer.dat2019-04-04 18:37 - 2019-04-04 18:37 - 000011568 _____ C:\Users\gaming\AppData\Local\InstallationConfiguration.xml2019-04-04 18:37 - 2019-04-04 18:37 - 000000000 ____D C:\ProgramData\Quoteexs2019-04-04 18:36 - 2019-04-04 20:05 - 000000000 ____D C:\ProgramData\Quoteex2019-04-04 18:36 - 2019-04-04 18:36 - 007901696 _____ C:\Users\louis\AppData\Local\agent.dat2019-04-04 18:36 - 2019-04-04 18:36 - 002035759 _____ C:\Users\louis\AppData\Local\Hotsailphase.tst2019-04-04 18:36 - 2019-04-04 18:36 - 000126464 _____ C:\Users\louis\AppData\Local\noah.dat2019-04-04 18:36 - 2019-04-04 18:36 - 000070992 _____ C:\Users\louis\AppData\Local\Config.xml2019-04-04 18:36 - 2019-04-04 18:36 - 000018432 _____ C:\Users\louis\AppData\Local\Main.dat2019-04-04 18:36 - 2019-04-04 18:36 - 000005568 _____ C:\Users\louis\AppData\Local\md.xml2019-04-04 18:36 - 2019-04-04 18:36 - 000000000 ____D C:\Users\gaming\AppData\Roaming\DropboxOEM2019-04-04 18:36 - 2019-04-04 18:36 - 000000000 ____D C:\Users\gaming\AppData\Local\DropboxOEM2019-04-04 18:35 - 2019-04-04 18:35 - 001632256 _____ C:\Users\louis\AppData\Local\Matcore.exe2019-04-04 18:35 - 2019-04-04 18:35 - 001632256 _____ C:\Users\louis\AppData\Local\Hotsailphase.exe2019-04-04 18:35 - 2019-04-04 18:35 - 000722944 _____ C:\Users\louis\AppData\Local\sha.db2019-04-04 18:35 - 2019-04-04 18:35 - 000278510 _____ C:\Users\louis\AppData\Local\Matcore.tst2019-04-04 18:35 - 2019-04-04 18:35 - 000140800 _____ C:\Users\louis\AppData\Local\installer.dat2019-04-04 18:35 - 2019-04-04 18:35 - 000016416 _____ C:\Users\louis\AppData\Local\InstallationConfiguration.xml2019-04-04 18:31 - 2019-04-04 18:32 - 002537664 _____ C:\Users\gaming\Downloads\SpyHunter 5 Crack(1).zip2019-04-04 18:30 - 2019-04-04 18:31 - 002537664 _____ C:\Users\gaming\Downloads\SpyHunter 5 Crack.zip.part2019-04-04 18:30 - 2019-04-04 18:30 - 000000000 _____ C:\Users\gaming\Downloads\SpyHunter 5 Crack.zip2019-04-04 13:27 - 2019-04-04 14:27 - 000000000 ____D C:\Users\gaming\AppData\Local\Game Dev Tycoon - Steam2019-04-04 12:54 - 2019-04-09 21:21 - 000000000 ____D C:\Users\gaming\Downloads\Game.Dev.Tycoon.v1.6.152019-04-04 12:13 - 2019-04-04 12:20 - 134146301 ____R C:\Users\gaming\Downloads\Game.Dev.Tycoon.v1.6.15.rar2019-04-04 12:12 - 2019-04-04 12:12 - 000000000 ____D C:\Users\gaming\AppData\Local\node-webkit2019-04-04 11:21 - 2019-04-04 12:03 - 002667320 _____ (BitTorrent Inc.) C:\Users\gaming\Downloads\BitTorrent.exe2019-04-04 11:09 - 2019-04-04 11:09 - 000012214 _____ C:\Users\gaming\Documents\cc_20190404_110929.reg2019-04-04 10:50 - 2019-04-04 10:50 - 000001178 _____ C:\Users\Public\Desktop\Garena.lnk2019-04-04 10:11 - 2019-04-04 10:12 - 000004322 _____ C:\Users\louis\Documents\cc_20190404_101156.reg2019-04-04 10:10 - 2019-04-04 10:10 - 000072508 _____ C:\Users\louis\Documents\cc_20190404_101044.reg2019-04-04 10:09 - 2019-04-04 10:09 - 001287374 _____ C:\Users\louis\Documents\cc_20190404_100919.reg2019-04-04 10:07 - 2019-04-04 10:07 - 000000000 ____D C:\Program Files\AVAST Software2019-04-04 10:06 - 2019-04-11 23:50 - 000000000 ____D C:\Program Files\CCleaner2019-04-04 10:06 - 2019-04-08 11:52 - 000002890 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC2019-04-04 10:06 - 2019-04-04 10:06 - 000000872 _____ C:\Users\Public\Desktop\CCleaner.lnk2019-04-04 10:06 - 2019-04-04 10:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner2019-04-04 10:02 - 2019-04-04 10:03 - 021211144 ____N (Piriform Software Ltd) C:\Users\gaming\Downloads\cctrialsetup.exe2019-04-04 09:46 - 2019-04-04 09:46 - 000000000 ____D C:\Users\gaming\AppData\Roaming\WinRAR2019-04-04 09:46 - 2019-02-18 13:15 - 000729648 ____N (Sysinternals - www.sysinternals.com) C:\Users\gaming\Downloads\Autoruns.exe2019-04-04 09:46 - 2019-02-18 13:15 - 000645680 ____N (Sysinternals - www.sysinternals.com) C:\Users\gaming\Downloads\autorunsc.exe2019-04-04 09:46 - 2019-02-18 13:15 - 000050512 ____N C:\Users\gaming\Downloads\autoruns.chm2019-04-04 09:46 - 2019-02-18 13:14 - 000857648 ____N (Sysinternals - www.sysinternals.com) C:\Users\gaming\Downloads\Autoruns64.exe2019-04-04 09:46 - 2019-02-18 13:14 - 000760576 ____N (Sysinternals - www.sysinternals.com) C:\Users\gaming\Downloads\autorunsc64.exe2019-04-04 09:46 - 2019-02-18 13:14 - 000747272 ____N (Sysinternals - www.sysinternals.com) C:\Users\gaming\Downloads\Autoruns64.dll2019-04-04 09:46 - 2017-11-16 11:34 - 000007490 ____N C:\Users\gaming\Downloads\Eula.txt2019-04-04 09:45 - 2019-04-04 09:45 - 001640992 _____ C:\Users\gaming\Downloads\Autoruns.zip2019-04-04 09:26 - 2019-04-04 09:26 - 000000000 ____D C:\Program Files\Malwarebytes2019-04-04 09:23 - 2019-04-04 09:25 - 062591336 _____ (Malwarebytes ) C:\Users\gaming\Downloads\mb3-setup-consumer-3.7.1.2839-1.0.563-1.0.9988.exe2019-04-04 09:18 - 2019-04-12 14:11 - 000000000 ____D C:\Users\gaming\AppData\LocalLow\Mozilla2019-04-04 09:18 - 2019-04-04 09:18 - 000000000 ____D C:\Users\gaming\AppData\Roaming\Mozilla2019-04-04 09:18 - 2019-04-04 09:18 - 000000000 ____D C:\Users\gaming\AppData\Local\Mozilla2019-04-04 00:12 - 2019-04-04 00:12 - 000000000 ____D C:\Users\gaming\AppData\Local\Comms2019-04-03 23:36 - 2019-04-03 23:36 - 000000000 ____D C:\Users\gaming\AppData\Local\CEF2019-04-03 23:29 - 2019-04-03 23:29 - 000000000 ____D C:\Users\gaming\AppData\Local\OneDrive2019-04-03 23:28 - 2019-04-03 23:31 - 073112880 ____N (Garena) C:\Users\gaming\Downloads\Garena-v2.0.exe2019-04-03 23:23 - 2019-04-05 22:13 - 000005920 _____ C:\Users\louis\Desktop\Rkill.txt2019-04-03 23:23 - 2019-04-03 23:23 - 000003382 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3470749901-1448784153-1402439068-10092019-04-03 23:23 - 2019-04-03 23:23 - 000002377 _____ C:\Users\gaming\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk2019-04-03 23:19 - 2019-04-09 23:07 - 000000000 ____D C:\Users\gaming\AppData\Local\CrashDumps2019-04-03 23:18 - 2019-04-03 23:18 - 000000000 ____D C:\Users\gaming\AppData\Local\DBG2019-04-03 23:14 - 2019-04-03 23:14 - 000000000 ____D C:\WINDOWS\System32\Tasks\S-1-5-21-3470749901-1448784153-1402439068-10092019-04-03 23:12 - 2019-04-03 23:23 - 000000000 ___RD C:\Users\gaming\OneDrive2019-04-03 23:11 - 2019-04-03 23:11 - 000000000 ____D C:\Users\gaming\AppData\Roaming\IObit2019-04-03 23:10 - 2019-04-03 23:10 - 000000000 __SHD C:\Users\gaming\IntelGraphicsProfiles2019-04-03 23:10 - 2019-04-03 23:10 - 000000000 ___HD C:\Users\gaming\MicrosoftEdgeBackups2019-04-03 23:10 - 2019-04-03 23:10 - 000000000 ____D C:\Users\gaming\AppData\Local\MicrosoftEdge2019-04-03 23:10 - 2019-04-03 23:10 - 000000000 ____D C:\Users\gaming\AppData\Local\D3DSCache2019-04-03 23:09 - 2019-04-03 23:30 - 000000000 ____D C:\Users\gaming\AppData\Local\Packages2019-04-03 23:09 - 2019-04-03 23:09 - 000000000 ___RD C:\Users\gaming\3D Objects2019-04-03 23:09 - 2019-04-03 23:09 - 000000000 ____D C:\Users\gaming\AppData\Local\VirtualStore2019-04-03 23:09 - 2019-04-03 23:09 - 000000000 ____D C:\Users\gaming\AppData\Local\Publishers2019-04-03 23:08 - 2019-04-11 18:42 - 000000000 ____D C:\Users\gaming2019-04-03 23:08 - 2019-04-03 23:10 - 000000000 ____D C:\Users\gaming\AppData\Local\ConnectedDevicesPlatform2019-04-03 23:08 - 2019-04-03 23:08 - 000000020 ___SH C:\Users\gaming\ntuser.ini2019-04-03 23:08 - 2019-02-22 19:57 - 000000000 ___HD C:\Users\gaming\Documents\hp.system.package.metadata2019-04-03 23:08 - 2019-02-22 19:57 - 000000000 ___HD C:\Users\gaming\Documents\hp.applications.package.appdata2019-04-03 23:08 - 2019-02-22 19:57 - 000000000 ____D C:\Users\gaming\AppData\Roaming\Adobe2019-04-03 23:08 - 2019-02-22 19:57 - 000000000 ____D C:\Users\gaming\AppData\Local\Microsoft Help2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ C:\Users\gaming\RFSVTIVY-DECRYPT.txt2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ C:\Users\gaming\Downloads\RFSVTIVY-DECRYPT.txt2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ C:\Users\gaming\Documents\RFSVTIVY-DECRYPT.txt2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ C:\Users\gaming\AppData\Roaming\RFSVTIVY-DECRYPT.txt2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ C:\Users\gaming\AppData\Roaming\Microsoft\Windows\Start Menu\RFSVTIVY-DECRYPT.txt2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ C:\Users\gaming\AppData\RFSVTIVY-DECRYPT.txt2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ C:\Users\gaming\AppData\Local\RFSVTIVY-DECRYPT.txt2019-04-03 15:46 - 2019-04-03 15:46 - 000000000 ____D C:\Users\louis\AppData\Local\Introversion2019-04-03 12:27 - 2019-04-03 12:27 - 000000000 ___HD C:\OneDriveTemp2019-04-03 11:46 - 2019-04-03 11:46 - 000000000 ____D C:\Users\louis\Documents\GTA San Andreas User Files2019-04-03 11:46 - 2019-04-03 11:46 - 000000000 ____D C:\Users\louis\AppData\Local\modloader2019-04-03 11:46 - 2019-04-03 11:46 - 000000000 ____D C:\ProgramData\modloader2019-04-03 09:58 - 2019-04-04 20:04 - 000000000 ____D C:\Users\louis\AppData\Roaming\DMCache2019-04-03 09:58 - 2019-04-03 10:00 - 000000000 ____D C:\Users\louis\AppData\Roaming\IDM2019-04-03 09:58 - 2019-04-03 09:58 - 000000000 ____D C:\ProgramData\IDM2019-04-03 09:57 - 2019-04-10 11:11 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager2019-04-03 09:57 - 2019-04-03 09:57 - 000000000 ____D C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager2019-04-03 09:57 - 2019-04-03 09:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager2019-04-02 22:55 - 2019-04-02 22:55 - 000000000 ____D C:\Users\louis\AppData\Roaming\Ian MacLarty2019-04-02 22:51 - 2019-04-02 22:51 - 000000000 ____D C:\Users\louis\AppData\LocalLow\Majorariatto2019-04-02 21:39 - 2019-04-02 21:40 - 000000000 ____D C:\Users\louis\AppData\Roaming\audacity2019-04-02 21:39 - 2019-04-02 21:39 - 000000000 ____D C:\Users\louis\AppData\Local\Audacity2019-04-02 16:07 - 2019-04-05 14:46 - 000000000 ____D C:\Users\louis\AppData\Local\Game Dev Tycoon - Steam2019-04-02 15:59 - 2019-04-02 15:59 - 000000043 _____ C:\Users\louis\AppData\Roaming\SiMPLEX.ini2019-04-02 15:59 - 2019-04-02 15:59 - 000000000 ____D C:\SiMPLEX.Release.Name2019-04-02 15:53 - 2019-04-02 15:53 - 025929258 _____ C:\Users\louis\Documents\disk2.pak2019-04-02 15:21 - 2019-04-02 15:21 - 000000000 ____D C:\Users\louis\AppData\Roaming\Smart Install Maker2019-04-02 15:10 - 2019-04-02 15:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Install Maker 5.042019-04-02 15:10 - 2019-04-02 15:10 - 000000000 ____D C:\Program Files (x86)\Smart Install Maker2019-04-02 14:48 - 2019-04-02 14:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip2019-04-02 14:48 - 2019-04-02 14:48 - 000000000 ____D C:\Program Files\7-Zip2019-04-02 11:14 - 2019-04-02 11:14 - 000000000 ____D C:\Users\louis\AppData\Roaming\java2019-04-02 11:12 - 2019-04-04 10:25 - 000000000 ____D C:\Users\louis\AppData\Roaming\.minecraft2019-04-02 11:11 - 2019-04-02 11:10 - 000110968 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-64.dll2019-04-02 11:10 - 2019-04-02 11:10 - 000110968 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll2019-04-02 11:09 - 2019-04-02 11:09 - 000000000 ____D C:\Program Files\Java2019-04-01 23:31 - 2019-04-06 13:56 - 000000364 _____ C:\WINDOWS\Tasks\HPCeeScheduleForlouis.job2019-04-01 23:31 - 2019-04-05 23:31 - 000003256 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForlouis2019-03-31 13:34 - 2019-04-04 09:51 - 000000000 ____D C:\Program Files (x86)\Counter-Strike2019-03-30 19:44 - 2019-03-30 19:44 - 000004210 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 15535838542019-03-30 19:44 - 2019-03-30 19:44 - 000001438 _____ C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk2019-03-28 16:22 - 2019-03-28 16:22 - 000003946 _____ C:\WINDOWS\System32\Tasks\BlueStacksHelper2019-03-28 16:11 - 2019-03-28 16:11 - 000003380 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3470749901-1448784153-1402439068-10082019-03-28 16:11 - 2019-03-28 16:11 - 000002374 _____ C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk2019-03-28 16:02 - 2019-03-28 16:02 - 000001523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk2019-03-28 15:58 - 2019-03-28 16:02 - 000000000 ____D C:\ProgramData\BlueStacksSetup2019-03-28 15:58 - 2019-03-28 16:01 - 000000000 ____D C:\ProgramData\BlueStacks2019-03-28 15:57 - 2019-03-28 16:00 - 000000000 ____D C:\Users\louis\AppData\Local\Bluestacks2019-03-28 11:07 - 2019-03-28 11:07 - 000000301 _____ C:\Users\louis\d4ac4633ebd6440fa397b84f1bc94a3c.7z2019-03-28 11:07 - 2019-03-28 11:07 - 000000000 ____D C:\Users\louis\AppData\Local\SKIDROW2019-03-28 06:36 - 2019-04-04 15:45 - 000000000 ____D C:\Program Files (x86)\ProxyGate2019-03-27 19:01 - 2019-03-27 19:01 - 000000000 ____D C:\RagnoTech™ Software Solutions2019-03-27 15:09 - 2019-03-27 15:09 - 000000000 ____D C:\Users\louis\AppData\LocalLow\Squeaky Wheel2019-03-27 15:02 - 2019-03-27 15:02 - 000000000 ____D C:\Users\louis\AppData\LocalLow\The Irregular Corp2019-03-27 07:50 - 2019-03-27 07:50 - 000000000 ____D C:\Users\louis\AppData\LocalLow\SKS2019-03-27 06:40 - 2019-04-05 11:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Forest2019-03-27 06:35 - 2019-03-28 06:35 - 000000000 ____D C:\Users\louis\AppData\Roaming\The.Forest.v1.08.[REPACK]2019-03-26 15:52 - 2019-04-05 11:51 - 000000000 ____D C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\Nox2019-03-26 15:52 - 2019-03-28 10:55 - 000000000 ____D C:\Users\louis\.BigNox2019-03-26 15:52 - 2019-03-26 15:52 - 000000000 ____D C:\Program Files (x86)\Bignox2019-03-26 15:05 - 2019-03-26 15:05 - 000000000 ____D C:\Users\louis\AppData\Local\Opera Software2019-03-26 15:04 - 2019-03-26 15:04 - 000004464 _____ C:\WINDOWS\System32\Tasks\Opera scheduled assistant Autoupdate 15535838732019-03-26 15:01 - 2019-04-05 15:11 - 000000000 ____D C:\Users\louis\AppData\Roaming\BitTorrent2019-03-26 15:01 - 2019-03-26 15:01 - 000000907 _____ C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk2019-03-26 15:01 - 2019-03-26 15:01 - 000000000 ____D C:\Users\louis\AppData\Roaming\Opera Software2019-03-26 14:57 - 2019-03-26 14:57 - 000000066 _____ C:\Users\louis\inittk.ini2019-03-26 14:56 - 2019-03-26 14:56 - 000000000 ____D C:\Users\louis\Nox_share2019-03-26 14:48 - 2019-03-26 14:48 - 000000000 ____D C:\Users\louis\AppData\LocalLow\IObit2019-03-26 07:32 - 2019-03-26 07:32 - 000746888 _____ (COMODO) C:\WINDOWS\SysWOW64\guard32.dll2019-03-26 07:32 - 2019-03-26 07:32 - 000052896 _____ (COMODO) C:\WINDOWS\system32\cmdcsr.dll2019-03-26 07:31 - 2019-03-26 07:31 - 000988504 _____ (COMODO) C:\WINDOWS\system32\guard64.dll2019-03-26 07:29 - 2019-03-26 07:29 - 000514752 _____ (COMODO) C:\WINDOWS\system32\cmdvrt64.dll2019-03-26 07:27 - 2019-03-26 07:27 - 000373952 _____ (COMODO) C:\WINDOWS\SysWOW64\cmdvrt32.dll2019-03-26 00:02 - 2019-03-26 00:02 - 000000000 ____D C:\Users\louis\AppData\Local\HP_Development_Company,_L2019-03-25 23:56 - 2019-03-25 23:58 - 000000000 ____D C:\Users\louis\AppData\Roaming\hpqLog2019-03-25 23:56 - 2019-03-25 23:56 - 000000000 ____D C:\Users\louis\AppData\Local\Hewlett-Packard2019-03-25 20:21 - 2019-03-28 10:56 - 000000000 ____D C:\Users\louis\.android2019-03-25 20:19 - 2019-03-26 15:02 - 000000000 ____D C:\Program Files (x86)\New folder2019-03-25 19:13 - 2019-03-25 19:13 - 000000000 ____D C:\Users\louis\AppData\Local\ElevatedDiagnostics2019-03-24 18:17 - 2019-03-24 18:17 - 000000000 ____D C:\Users\louis\AppData\Roaming\WildTangent2019-03-24 14:59 - 2019-03-24 14:59 - 000000000 ____D C:\Users\louis\AppData\Local\Telerik2019-03-24 14:56 - 2019-03-24 14:59 - 000000000 ____D C:\Users\louis\Documents\Fiddler22019-03-24 14:51 - 2019-03-24 14:51 - 000000000 ____D C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook2019-03-24 14:51 - 2019-03-24 14:51 - 000000000 ____D C:\Users\louis\AppData\Local\Facebook2019-03-24 12:19 - 2019-03-24 12:19 - 000000045 _____ C:\Users\louis\nuuid.ini2019-03-24 12:19 - 2019-03-24 12:19 - 000000041 _____ C:\Users\louis\inst.ini2019-03-24 12:07 - 2019-03-28 10:55 - 000000000 ____D C:\Users\louis\vmlogs2019-03-24 12:06 - 2019-03-28 11:07 - 000000000 ____D C:\Users\louis\AppData\Local\Nox2019-03-24 11:37 - 2019-03-24 11:37 - 000000000 ____D C:\Users\louis\AppData\Roaming\BluestacksCN2019-03-24 10:03 - 2019-03-28 16:01 - 000000000 ____D C:\Program Files (x86)\BlueStacks2019-03-23 13:01 - 2019-03-23 13:30 - 000000000 ____D C:\Users\louis\AppData\Roaming\CC2019-03-23 13:01 - 2019-03-23 13:01 - 000000000 ____D C:\Users\louis\AppData\Local\NetEase2019-03-23 11:38 - 2019-03-23 13:01 - 000000000 ____D C:\Users\louis\AppData\Roaming\Netease2019-03-22 22:58 - 2019-03-22 22:58 - 000002311 _____ C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fiddler ScriptEditor.lnk2019-03-22 22:58 - 2019-03-22 22:58 - 000002167 _____ C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fiddler 4.lnk2019-03-22 21:51 - 2019-03-22 21:51 - 000253042 _____ C:\WINDOWS\SysWOW64\lua52.dll2019-03-22 21:51 - 2019-03-22 21:51 - 000167936 _____ C:\WINDOWS\SysWOW64\lua5.1.dll2019-03-22 21:48 - 2019-03-22 21:48 - 000000000 ____D C:\Users\louis\AppData\Roaming\GamingOnSteroids2019-03-22 19:07 - 2019-03-22 19:07 - 000000000 ____D C:\ProgramData\D93C74EB-2573-C874-0B38-F7440BDFAE152019-03-22 19:07 - 2019-03-22 19:07 - 000000000 ____D C:\ProgramData\AF934808-1990-BEDB-E804-5832E8E301632019-03-22 19:06 - 2019-03-24 03:39 - 000000000 ____D C:\Program Files (x86)\Multitimer2019-03-22 19:06 - 2019-03-23 08:23 - 000000000 ____D C:\Program Files (x86)\Saver2019-03-22 19:06 - 2019-03-22 21:31 - 000000000 ____D C:\Program Files\Homeville2019-03-22 19:04 - 2019-03-22 19:04 - 000000000 ____D C:\Users\louis\AppData\Roaming\WinRAR2019-03-22 16:59 - 2019-03-22 16:59 - 000000000 ____D C:\Users\louis\AppData\Roaming\Macromedia2019-03-22 16:45 - 2019-03-22 16:45 - 000000000 ____D C:\Users\louis\Documents\DragonNest2019-03-22 13:28 - 2019-03-22 13:28 - 000000000 ____D C:\Users\louis\Documents\League of Legends2019-03-21 22:46 - 2018-12-20 18:05 - 000229296 _____ (Tonec Inc.) C:\WINDOWS\system32\Drivers\idmwfp.sys2019-03-21 20:41 - 2019-03-21 20:41 - 000000000 ____D C:\Users\louis\AppData\Roaming\Hewlett-Packard2019-03-21 20:34 - 2019-03-21 20:34 - 000000258 __RSH C:\Users\louis\ntuser.pol2019-03-21 20:06 - 2019-03-21 20:06 - 000000000 ____D C:\Users\louis\AppData\Local\PlaceholderTileLogoFolder2019-03-21 20:03 - 2019-03-21 20:03 - 000000000 ____D C:\Users\louis\AppData\Roaming\RenPy2019-03-21 18:51 - 2019-04-07 15:47 - 000000000 ____D C:\Users\louis\AppData\LocalLow\Mozilla2019-03-21 18:51 - 2019-03-21 18:51 - 000000000 ____D C:\Users\louis\AppData\Roaming\Mozilla2019-03-21 18:51 - 2019-03-21 18:51 - 000000000 ____D C:\Users\louis\AppData\Local\Mozilla2019-03-21 18:51 - 2019-03-21 18:51 - 000000000 ____D C:\Users\123\AppData\Local\Mozilla2019-03-21 18:50 - 2019-03-28 21:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service2019-03-21 18:50 - 2019-03-28 15:33 - 000001018 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk2019-03-21 18:50 - 2019-03-28 15:33 - 000000000 ____D C:\Program Files\Mozilla Firefox2019-03-21 18:50 - 2019-03-21 18:51 - 000000000 ____D C:\ProgramData\Mozilla2019-03-21 18:42 - 2019-03-21 18:42 - 000004590 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier2019-03-21 18:39 - 2019-03-26 11:45 - 000000000 ____D C:\Users\louis\AppData\Local\Adobe2019-03-21 13:29 - 2019-04-04 20:17 - 000000000 ____D C:\Users\louis\AppData\Local\CrashDumps2019-03-19 19:05 - 2019-03-19 19:05 - 000002488 _____ C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_louis2019-03-19 19:05 - 2019-03-19 19:05 - 000000306 _____ C:\WINDOWS\Tasks\Uninstaller_SkipUac_louis.job2019-03-19 16:55 - 2019-03-19 16:55 - 000000000 ____D C:\Users\louis\AppData\Local\OneDrive2019-03-19 02:25 - 2019-03-19 02:25 - 000000000 ____D C:\Users\louis\AppData\Roaming\Sun2019-03-19 02:25 - 2019-03-19 02:25 - 000000000 ____D C:\Users\louis\AppData\LocalLow\Sun2019-03-18 20:22 - 2019-03-18 20:22 - 000849048 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmdguard.sys2019-03-18 20:22 - 2019-03-18 20:22 - 000134280 _____ (COMODO) C:\WINDOWS\system32\Drivers\inspect.sys2019-03-18 20:22 - 2019-03-18 20:22 - 000051672 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmdhlp.sys2019-03-18 20:22 - 2019-03-18 20:22 - 000043416 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmderd.sys2019-03-18 19:57 - 2019-03-18 19:57 - 000000000 ____D C:\Users\louis\AppData\LocalLow\SHOOT2019-03-18 19:52 - 2019-03-19 17:19 - 000000000 ____D C:\Users\louis\AppData\Local\TerritoryIdl2_22019-03-18 19:50 - 2019-03-18 19:50 - 000000000 ____D C:\Users\louis\AppData\Local\Steam2019-03-18 07:04 - 2019-04-10 12:16 - 000000000 ____D C:\Garena2019-03-18 07:04 - 2019-03-18 07:04 - 000000000 __SHD C:\Users\louis\IntelGraphicsProfiles2019-03-18 07:01 - 2019-03-18 07:01 - 000000000 ____D C:\Users\louis\AppData\Local\CEF2019-03-18 06:17 - 2019-03-18 06:17 - 000000000 ____D C:\Users\louis\AppData\Local\Comms2019-03-18 06:13 - 2019-04-03 12:27 - 000000000 ___RD C:\Users\louis\OneDrive2019-03-18 06:03 - 2019-04-03 22:46 - 000000000 ____D C:\Users\louis\AppData\Roaming\IObit2019-03-18 06:03 - 2019-03-18 06:03 - 000000000 ____D C:\Users\louis\AppData\Local\DBG2019-03-18 06:01 - 2019-03-18 06:01 - 000000000 ____D C:\Users\louis\AppData\Local\D3DSCache2019-03-18 06:00 - 2019-03-18 06:00 - 000000000 ___HD C:\Users\louis\MicrosoftEdgeBackups2019-03-18 06:00 - 2019-03-18 06:00 - 000000000 ____D C:\Users\louis\AppData\Local\MicrosoftEdge2019-03-18 05:59 - 2019-03-18 05:59 - 000000000 ____D C:\Users\louis\AppData\Local\Publishers2019-03-18 05:58 - 2019-04-02 21:28 - 000000000 ____D C:\Users\louis\AppData\Local\Packages2019-03-18 05:58 - 2019-03-31 13:37 - 000000000 ____D C:\Users\louis\AppData\Local\VirtualStore2019-03-18 05:58 - 2019-03-18 05:58 - 000000000 ___RD C:\Users\louis\3D Objects2019-03-18 05:58 - 2019-03-18 05:58 - 000000000 ____D C:\Users\louis\AppData\Local\Google2019-03-18 05:58 - 2019-03-18 05:58 - 000000000 ____D C:\Users\louis\AppData\Local\BraveSoftware2019-03-18 05:57 - 2019-04-08 16:13 - 000000000 ____D C:\Users\louis2019-03-18 05:57 - 2019-04-02 21:28 - 000000000 ____D C:\Users\louis\AppData\Local\ConnectedDevicesPlatform2019-03-18 05:57 - 2019-03-26 11:45 - 000000000 ____D C:\Users\louis\AppData\Roaming\Adobe2019-03-18 05:57 - 2019-03-18 05:57 - 000000020 ___SH C:\Users\louis\ntuser.ini2019-03-18 05:57 - 2019-02-22 19:57 - 000000000 ___HD C:\Users\louis\Documents\hp.system.package.metadata2019-03-18 05:57 - 2019-02-22 19:57 - 000000000 ___HD C:\Users\louis\Documents\hp.applications.package.appdata2019-03-18 05:57 - 2019-02-22 19:57 - 000000000 ____D C:\Users\louis\AppData\Local\Microsoft Help2019-03-18 05:57 - 2019-02-20 21:50 - 000008730 _____ C:\Users\louis\RFSVTIVY-DECRYPT.txt2019-03-18 05:57 - 2019-02-20 21:50 - 000008730 _____ C:\Users\louis\Documents\RFSVTIVY-DECRYPT.txt2019-03-18 05:57 - 2019-02-20 21:50 - 000008730 _____ C:\Users\louis\AppData\Roaming\RFSVTIVY-DECRYPT.txt2019-03-18 05:57 - 2019-02-20 21:50 - 000008730 _____ C:\Users\louis\AppData\Roaming\Microsoft\Windows\Start Menu\RFSVTIVY-DECRYPT.txt2019-03-18 05:57 - 2019-02-20 21:50 - 000008730 _____ C:\Users\louis\AppData\RFSVTIVY-DECRYPT.txt2019-03-18 05:57 - 2019-02-20 21:50 - 000008730 _____ C:\Users\louis\AppData\Local\RFSVTIVY-DECRYPT.txt2019-03-17 21:35 - 2019-03-17 21:35 - 000000222 _____ C:\Users\123\Desktop\Rock Paper Scissors Champion.url2019-03-17 21:27 - 2019-03-17 21:27 - 000000000 ____D C:\Users\123\AppData\Roaming\Godot2019-03-17 21:25 - 2019-03-17 21:25 - 000000223 _____ C:\Users\123\Desktop\HYPERFIGHT Max Battle.url2019-03-17 21:02 - 2019-03-17 21:20 - 000000000 ____D C:\Users\123\AppData\Local\TerritoryIdl2_22019-03-17 20:40 - 2019-03-17 20:40 - 000000223 _____ C:\Users\123\Desktop\Territory Idle.url2019-03-17 05:49 - 2019-03-17 05:49 - 000000000 ____D C:\Users\123\AppData\LocalLow\SHOOT2019-03-17 04:59 - 2019-03-17 17:23 - 000000000 ____D C:\Users\123\Desktop\cfg2019-03-17 03:14 - 2019-03-17 03:14 - 000000223 _____ C:\Users\123\Desktop\Its Simple, SHOOT.url2019-03-16 16:38 - 2019-03-17 21:35 - 000000000 ____D C:\Users\123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam2019-03-16 16:38 - 2019-03-17 06:00 - 000000219 _____ C:\Users\123\Desktop\Counter-Strike Global Offensive.url2019-03-16 16:38 - 2019-03-16 16:38 - 001172256 _____ C:\Users\123\Desktop\csgo.exe2019-03-16 16:01 - 2019-03-16 16:01 - 000003374 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3470749901-1448784153-1402439068-10032019-03-16 16:01 - 2019-03-16 16:01 - 000002368 _____ C:\Users\123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk2019-03-16 15:59 - 2019-03-16 15:59 - 000000000 ____D C:\Users\123\AppData\Local\Steam2019-03-16 15:36 - 2019-03-16 15:37 - 001573568 _____ C:\Users\123\Downloads\SteamSetup.exe2019-03-16 12:23 - 2019-03-16 12:23 - 000000000 ____D C:\Users\123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\cZERO2019-03-16 10:40 - 2019-04-04 10:19 - 000000000 ____D C:\Users\123\Documents\My Games2019-03-16 10:29 - 2019-03-16 10:31 - 000000000 ____D C:\Users\123\Documents\NFS SHIFT2019-03-16 10:24 - 2019-03-16 10:24 - 000000000 __RHD C:\Users\123\AppData\Roaming\SecuROM2019-03-16 04:05 - 2019-03-16 04:05 - 000000000 ____D C:\Users\123\AppData\Local\BitTorrentHelper2019-03-14 22:46 - 2019-03-14 22:46 - 000000000 _____ C:\Users\123\AppData\Local\9C4C4365-E566-4CA9-91DA-2B5440266AB3==================== One month (modified) ========(If an entry is included in the fixlist, the file/folder will be moved.)2019-04-12 14:30 - 2018-08-20 06:41 - 000000000 ____D C:\Users\123\AppData\Roaming\libraries2019-04-12 14:06 - 2018-04-12 07:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft2019-04-12 14:02 - 2018-06-23 17:32 - 000002644 _____ C:\WINDOWS\system32\PerfStringBackup.INI2019-04-12 13:55 - 2018-06-23 18:17 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT2019-04-12 13:55 - 2018-06-23 17:23 - 000000000 ____D C:\WINDOWS\system32\SleepStudy2019-04-12 13:55 - 2018-04-12 07:38 - 000000000 ____D C:\Program Files\Common Files\system2019-04-11 19:03 - 2017-09-10 08:06 - 000000000 ____D C:\Program Files (x86)\YouTube By Click2019-04-11 00:39 - 2018-04-12 07:38 - 000000000 ____D C:\WINDOWS\system32\NDF2019-04-10 12:04 - 2017-09-10 13:40 - 000000000 ____D C:\Users\Guest2019-04-10 12:03 - 2017-09-10 13:40 - 000000000 ____D C:\Users\DefaultAccount2019-04-09 21:09 - 2018-06-23 17:40 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk2019-04-09 21:07 - 2018-06-23 17:33 - 000000000 ____D C:\Users\Yaokeroa2019-04-09 21:04 - 2016-07-29 20:33 - 000000000 __RHD C:\Users\Public\AccountPictures2019-04-09 13:08 - 2017-09-10 13:27 - 000000000 ____D C:\Users\Yaokeroa\AppData\Roaming\BitTorrent2019-04-09 13:02 - 2019-03-09 14:43 - 000000000 ____D C:\Users\Yaokeroa\AppData\LocalLow\BitTorrent2019-04-09 01:22 - 2018-08-11 08:13 - 000000000 ____D C:\Users\1232019-04-08 19:43 - 2018-04-12 05:04 - 000065536 _____ C:\WINDOWS\system32\config\ELAM2019-04-08 18:15 - 2019-01-30 17:58 - 000000000 ____D C:\Users\Yaokeroa\AppData\Roaming\Mozilla2019-04-08 18:07 - 2018-04-12 05:04 - 001835008 _____ C:\WINDOWS\system32\config\BBI2019-04-08 17:54 - 2018-04-12 07:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP2019-04-08 17:38 - 2018-06-23 17:33 - 000000000 ____D C:\Users\defaultuser02019-04-08 15:09 - 2018-04-12 07:38 - 000000000 ____D C:\WINDOWS\Registration2019-04-08 15:05 - 2018-06-09 08:06 - 000000000 ____D C:\ProgramData\COMODO2019-04-08 15:05 - 2018-04-07 21:39 - 000000000 ____D C:\Program Files (x86)\Comodo2019-04-08 14:02 - 2017-12-02 11:44 - 000000000 ____D C:\ProgramData\boost_interprocess2019-04-05 16:38 - 2017-03-21 02:34 - 000000000 ____D C:\ProgramData\Package Cache2019-04-05 15:33 - 2019-01-15 14:51 - 000000000 ____D C:\Users\Public\File Viewer Plus2019-04-05 11:55 - 2018-04-12 07:41 - 000000000 ____D C:\WINDOWS\Setup2019-04-05 11:55 - 2018-04-12 07:38 - 000000000 __RSD C:\WINDOWS\media2019-04-05 11:55 - 2018-04-12 07:38 - 000000000 ____D C:\WINDOWS\security2019-04-05 11:55 - 2018-04-12 07:38 - 000000000 ____D C:\WINDOWS\Help2019-04-05 11:55 - 2017-11-10 08:44 - 000000000 __RHD C:\MSOCache2019-04-05 11:51 - 2019-03-04 19:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mortal Kombat Complete Edition2019-04-05 11:51 - 2019-03-03 18:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DragonNest_SEA2019-04-05 11:51 - 2018-09-03 16:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Beat Cop2019-04-05 11:51 - 2018-08-27 17:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer Cortex2019-04-05 11:51 - 2018-08-26 09:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Empire Earth Gold Edition [GOG.com]2019-04-05 11:51 - 2018-08-18 14:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Terraria [GOG.com]2019-04-05 11:51 - 2018-08-16 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prison Architect [GOG.com]2019-04-05 11:51 - 2018-06-30 16:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO2019-04-05 11:51 - 2018-05-30 18:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPcap2019-04-05 11:51 - 2018-03-26 22:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin2019-04-04 15:45 - 2017-12-20 10:43 - 000000000 ____D C:\ProgramData\AVAST Software2019-04-04 10:48 - 2017-12-02 11:43 - 000000000 ____D C:\Program Files (x86)\Garena2019-04-04 10:44 - 2018-06-23 17:23 - 005146352 _____ C:\WINDOWS\system32\FNTCACHE.DAT2019-04-04 10:42 - 2019-03-01 21:19 - 000000000 ____D C:\Program Files (x86)\RocketDock2019-04-04 10:19 - 2017-03-21 02:39 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information2019-04-03 23:48 - 2017-12-02 11:44 - 000000000 ____D C:\ProgramData\Garena2019-04-03 23:40 - 2017-12-02 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garena2019-04-03 20:45 - 2019-03-10 14:13 - 000000000 ____D C:\Users\123\AppData\Local\ZPN Connect2019-04-02 11:11 - 2018-09-06 05:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java2019-03-31 15:20 - 2017-10-24 07:31 - 000000000 ____D C:\ProgramData\ProductData2019-03-30 18:11 - 2019-03-01 08:21 - 000000000 ____D C:\Games2019-03-28 10:36 - 2018-01-21 12:24 - 000000000 ____D C:\old system2019-03-27 15:01 - 2018-02-20 09:40 - 000000000 ____D C:\Applications2019-03-27 15:00 - 2017-03-08 08:59 - 000000000 ___HD C:\hp2019-03-22 16:58 - 2018-04-12 07:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed2019-03-22 16:58 - 2018-04-12 07:38 - 000000000 ____D C:\WINDOWS\system32\Macromed2019-03-22 13:49 - 2018-04-12 07:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports2019-03-21 19:44 - 2019-03-12 22:39 - 000000000 ____D C:\Program Files (x86)\BraveSoftware2019-03-21 18:49 - 2017-09-10 02:38 - 000000000 ____D C:\Program Files (x86)\Google2019-03-21 18:48 - 2019-03-12 22:39 - 000000000 ____D C:\Users\123\AppData\Local\BraveSoftware2019-03-21 18:39 - 2018-08-11 08:21 - 000000000 ____D C:\Users\123\AppData\Local\Adobe2019-03-17 22:48 - 2019-02-28 22:00 - 000000000 ____D C:\Users\123\AppData\Roaming\BitTorrent Web2019-03-17 22:33 - 2019-02-28 22:05 - 000000000 ____D C:\Users\123\AppData\Roaming\uTorrent2019-03-17 22:32 - 2018-08-11 09:29 - 000000000 ____D C:\Users\123\AppData\Local\CrashDumps2019-03-17 22:31 - 2019-03-01 23:05 - 000000000 ____D C:\Users\123\AppData\Roaming\BITS2019-03-17 22:08 - 2019-03-12 22:44 - 000000000 ____D C:\Users\123\AppData\Local\Overwolf2019-03-17 22:06 - 2019-03-10 14:14 - 000000000 ____D C:\Users\123\AppData\Roaming\ZPN Connect2019-03-17 21:57 - 2018-09-14 16:38 - 000000000 ____D C:\Users\123\AppData\Roaming\RenPy2019-03-16 16:01 - 2018-08-11 12:15 - 000000000 ___RD C:\Users\123\OneDrive2019-03-16 10:23 - 2019-03-01 23:31 - 000000000 ____D C:\Users\123\AppData\Local\JDownloader 2.02019-03-16 07:04 - 2019-03-11 22:22 - 000000356 _____ C:\WINDOWS\Tasks\HPCeeScheduleFor123.job2019-03-16 04:22 - 2019-03-11 22:22 - 000003240 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleFor123==================== Files in the root of some directories =======2018-06-09 06:30 - 2018-03-13 17:17 - 000440512 _____ (COMODO) C:\ProgramData\cmdres.dll2018-02-21 05:36 - 2018-04-07 19:57 - 000000004 _____ () C:\ProgramData\lock.dat2019-02-18 05:04 - 2019-02-20 17:06 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll2019-02-18 05:05 - 2019-02-20 17:10 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll2019-02-20 19:33 - 2019-02-25 19:36 - 000009270 _____ () C:\Program Files\RFSVTIVY-DECRYPT.txt.yhzrubznr2019-02-25 19:36 - 2019-02-25 19:36 - 000008722 _____ () C:\Program Files\YHZRUBZNR-MANUAL.txt2019-02-20 19:33 - 2019-02-25 19:36 - 000009270 _____ () C:\Program Files (x86)\RFSVTIVY-DECRYPT.txt.yhzrubznr2019-02-25 19:36 - 2019-02-25 19:36 - 000008722 _____ () C:\Program Files (x86)\YHZRUBZNR-MANUAL.txt2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ () C:\Users\gaming\AppData\Roaming\RFSVTIVY-DECRYPT.txt2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ () C:\Users\gaming\AppData\Roaming\Microsoft\RFSVTIVY-DECRYPT.txt2019-04-04 18:37 - 2019-04-04 18:37 - 000011568 _____ () C:\Users\gaming\AppData\Local\InstallationConfiguration.xml2019-04-04 18:37 - 2019-04-04 18:37 - 000140800 _____ () C:\Users\gaming\AppData\Local\installer.dat2019-04-03 23:08 - 2019-02-20 21:50 - 000008730 _____ () C:\Users\gaming\AppData\Local\RFSVTIVY-DECRYPT.txt2019-04-04 18:37 - 2019-04-04 18:37 - 000722944 _____ () C:\Users\gaming\AppData\Local\sha.dbSome files in TEMP:====================2019-03-09 13:12 - 2019-03-10 17:31 - 000000000 _____ () C:\Users\123\AppData\Local\Temp\84bc1c93d310d534abe6b7c11e3cef0d.dll2019-03-09 13:12 - 2019-03-10 16:40 - 000000088 _____ () C:\Users\123\AppData\Local\Temp\c8122d78d6394ef8f66f37c9230bdfe1.dll2019-03-16 10:24 - 2019-03-16 10:24 - 000065536 _____ (Sony DADC Austria AG) C:\Users\123\AppData\Local\Temp\drm_dialogs.dll2019-03-16 10:24 - 2019-03-16 10:24 - 000208896 _____ (Sony DADC Austria AG) C:\Users\123\AppData\Local\Temp\drm_dyndata_7400008.dll2019-02-26 05:14 - 2019-02-26 05:14 - 073112880 _____ (Garena) C:\Users\123\AppData\Local\Temp\Garena-v2.0.exe2019-03-16 10:21 - 2019-03-16 10:21 - 000043520 _____ () C:\Users\123\AppData\Local\Temp\proxy_vole261438483241542662.dll2019-03-16 10:23 - 2019-03-16 10:23 - 000043520 _____ () C:\Users\123\AppData\Local\Temp\proxy_vole4738658526473263181.dll2019-03-16 10:23 - 2019-03-16 10:23 - 000043520 _____ () C:\Users\123\AppData\Local\Temp\proxy_vole516188270749450330.dll2019-03-16 10:23 - 2019-03-16 10:23 - 000043520 _____ () C:\Users\123\AppData\Local\Temp\proxy_vole7843383113293745618.dll2019-04-08 15:08 - 2019-04-08 15:08 - 000042248 _____ () C:\Users\gaming\AppData\Local\Temp\dragon_install.exe2019-04-08 15:08 - 2019-04-08 15:08 - 000124680 _____ () C:\Users\gaming\AppData\Local\Temp\dragon_register.exe2019-04-08 17:05 - 2019-04-08 17:05 - 000000000 _____ () C:\Users\gaming\AppData\Local\Temp\stsrvl.exe2019-04-06 14:30 - 2019-04-06 14:30 - 000069337 _____ () C:\Users\louis\AppData\Local\Temp\conres.dll2019-04-06 23:21 - 2019-04-06 23:21 - 001449008 _____ (Sysinternals - www.sysinternals.com) C:\Users\louis\AppData\Local\Temp\procexp64.exe2019-04-06 14:35 - 2019-04-06 14:35 - 000000014 _____ () C:\Users\louis\AppData\Local\Temp\update.exe2019-02-05 09:37 - 2019-02-05 09:37 - 001974624 _____ (Oracle Corporation) C:\Users\Yaokeroa\AppData\Local\Temp\jre-8u201-windows-au.exe==================== Bamital & volsnap ======================(There is no automatic fix for files that do not pass verification.)C:\WINDOWS\system32\winlogon.exe => File is digitally signedC:\WINDOWS\system32\wininit.exe => File is digitally signedC:\WINDOWS\explorer.exe => File is digitally signedC:\WINDOWS\SysWOW64\explorer.exe => File is digitally signedC:\WINDOWS\system32\svchost.exe => File is digitally signedC:\WINDOWS\SysWOW64\svchost.exe => File is digitally signedC:\WINDOWS\system32\services.exe => File is digitally signedC:\WINDOWS\system32\User32.dll => File is digitally signedC:\WINDOWS\SysWOW64\User32.dll => File is digitally signedC:\WINDOWS\system32\userinit.exe => File is digitally signedC:\WINDOWS\SysWOW64\userinit.exe => File is digitally signedC:\WINDOWS\system32\rpcss.dll => File is digitally signedC:\WINDOWS\system32\dnsapi.dll => File is digitally signedC:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signedC:\WINDOWS\system32\dllhost.exe => File is digitally signedC:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signedC:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signedLastRegBack: 2018-06-23 17:23==================== End of FRST.txt ============================
MS Visio Pro 2013 X64 Multilingual .rar
2ff7e9595c
Kommentare