Jump to content

Recommended Posts

Hello,

Every time I login into a chrome account for the first time, when the extensions are updated, I get this message that says "Tampermonkey" added "another program on your computer added an extension that may change the way Chrome works." I then immediately select "Remove from Chrome." This keeps happening, any ideas? I ran fulls scans with both malwarebytes and avast with nothing detected.

Thank you!

https://imgur.com/a/bEQv9NZ

Edited by SemperAye
forgot to add picture
Link to post
Share on other sites

  • Staff

***This is an automated reply***

Hi,

Thanks for posting in the Malware Removal for Windows Help forum. Being infected is not fun and can be very frustrating to resolve, but don't worry because we have a team of experts here help you!!

Note: Please be patient. When the site is busy it can take up to 48 hours before a malware removal helper can assist you. If no one has replied to your new topic after 48 hours please contact a Moderator or Administrator to let them know.

 

First, if you haven't done so, please run a Threat Scan with the latest version of Malwarebytes. This may resolve your malware infection issue without the need for additional support. Click "Reveal Hidden Contents" below for details:

Spoiler

Malwarebytes can detect and remove most malware with no further actions required for free.

If you do not have Malwarebytes, please download it here and install. Be sure to post back the log as shown below.

  1. Open Malwarebytes for Windows
  2. To the left, click Scan > Scan Types.
    image.png
  3. Select Threat Scan. Threat Scan is the most thorough and recommended scan method available.
    image.png
  4. Click Start Scan

Next, if you're still experiencing issues after running Malwarebytes, then technical logs will be required to assist you. Click "Reveal Hidden Contents" below and follow the instructions to run the Farbar Recovery Scan Tool:

Spoiler

Don't use any temporary file cleaners unless requested - this can cause data loss and make a recovery difficult.

Please download the Farbar Recovery Scan Tool here and save it to your desktop. Note: You need to run the version compatible with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit

  1. Double-click to run it. When the tool opens click Yes to the disclaimer.
  2. Press the Scan button.
    _frst_scan.jpg.d10e66dc03e35ede4fdcba12b
  3. It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  4. The first time the tool is run, it also makes another log (Addition.txt). If you've run it before it may not and you may need to select it manually.

Finally, attach the Malwarebytes Threat Scan, FRST.txt and Additional.txt logs to your reply and Follow this topic to get notified when an expert has replied. Click "Reveal Hidden Contents" below for details.

Note: If you are unable to attach files, please copy and past the contents of the requested files in your Reply instead. 

Spoiler

To save attachments, please click the link as shown below. You can click and drag the files to this bar or you can click the choose files, then browse to where your files are located, select them and click the Open button.

_mb_attach.jpg.a0465aaafd6cae688aa38ab16

 

After posting your new post, make sure you click the Follow button near the top right of this page, and select the option "An email when new content is posted Change how the notification is sent" so that you're alerted by email when someone has replied to your post.

_mb_follow.jpg.7868cc281f66ac22e919c2c48

_mb_follow_options.jpg.dcb79fc10aa35beb0

Please Note the Following:

  • One of our expert helpers will give you one-on-one assistance when one becomes available.
  • Refrain from making any further changes to your computer (such as Install/Uninstall programs, using special fix tools, delete files, edit the registry, etc...) unless advised by a malware removal helper. Doing so can result in system changes which may hinder the attempts by a helper to clean your machine.
  • Do not 'bump' or add a reply to your topic once it is started. Topics which appear to have replies are considered to have a helper assisting them and may be overlooked, resulting in a longer waiting period for help
  • If you're using Peer 2 Peer software such as uTorrent or similar, please completely disable it from running while being assisted here.

Troubleshooting Tips

Link to post
Share on other sites

Hello SemperAye and welcome to Malwarebytes,

Continue with the following:

If you do not have Malwarebytes installed do the following:

Download Malwarebytes version 3 from the following link:

https://www.malwarebytes.com/mwb-download/thankyou/

Double click on the installer and follow the prompts. If necessary select the Blue Help tab for video instructions....

When the install completes or Malwarebytes is already installed do the following:

Open Malwarebytes, select > "settings" > "protection tab"

Scroll down to "Scan Options" ensure Scan for Rootkits and Scan within Archives are both on....

Go back to "DashBoard" select the Blue "Scan Now" tab......

When the scan completes deal with any found entries...

To get the log from Malwarebytes do the following:
 
  • Click on the Report tab > from main interface.
  • Double click on the Scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have two options:
    Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
    Text file (*.txt) - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply

     
  • Please use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…


Next,

Download AdwCleaner by Malwarebytes onto your Desktop.

Or from this Mirror
 
  • Right-click on AdwCleaner.exe and select user posted imageRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all the active processes
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply


Next,

Download Farbar Recovery Scan Tool and save it to your desktop.

Alternative download option: http://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

If your security alerts to FRST either, accept the alert or turn your security off to allow FRST to run. It is not malicious or infected in any way...

Be aware FRST must be run from an account with Administrator status...
 
  • Double-click to run it. When the tool opens click Yes to disclaimer.(Windows 8/10 users will be prompted about Windows SmartScreen protection - click More information and Run.)
  • Make sure Addition.txt is checkmarked under "Optional scans"
    user posted image
     
  • Press Scan button to run the tool....
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also make a log named (Addition.txt) Please attach that log to your reply.


Let me see those logs in your reply...

Thank you,

Kevin....
Link to post
Share on other sites

Kevin,

Thank you.

# -------------------------------
# Malwarebytes AdwCleaner 7.1.1.0
# -------------------------------
# Build:    04-27-2018
# Database: 2018-05-14.1
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    05-17-2018
# Duration: 00:00:27
# OS:       Windows 10 Home
# Cleaned:  21
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\Program Files (x86)\INSTANTVIDEOARTICLES

***** [ Files ] *****

Deleted       C:\TOSTACK
Deleted       C:\END

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted       Ask
Deleted       Ask
Deleted       Ask
Deleted       Ask
Deleted       Ask
Deleted       Ask
Deleted       Ask
Deleted       Ask
Deleted       Ask
Deleted       AOL
Deleted       AOL
Deleted       AOL
Deleted       AOL
Deleted       AOL
Deleted       AOL
Deleted       AOL
Deleted       AOL
Deleted       AOL

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************


########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16.05.2018 01
Ran by sempe (administrator) on DESKTOP-THLJ3B4 (17-05-2018 20:12:30)
Running from C:\Users\sempe\Downloads
Loaded Profiles: sempe (Available Profiles: sempe & Guest-User)
Platform: Windows 10 Home Version 1709 16299.431 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k120836.inf_amd64_ccaf7e7e1e972b78\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
() C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture_DELL.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\k120836.inf_amd64_ccaf7e7e1e972b78\igfxEM.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1813.286.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(The Privoxy team - www.privoxy.org) C:\Program Files (x86)\Privoxy\privoxy.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.16299.428_none_1704c21831ffb4a8\TiWorker.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3348200 2015-07-09] (ELAN Microelectronics Corp.)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8848640 2016-02-05] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1419008 2016-02-05] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322120 2016-04-28] (Intel Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242904 2018-05-11] (AVAST Software)
HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [718256 2015-12-22] (Waves Audio Ltd.)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [315880 2018-01-05] (Adobe Systems, Incorporated)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2384984 2016-12-09] (Adobe Systems Incorporated)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3199776 2018-04-03] (Valve Corporation)
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46214128 2018-04-12] ()
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\Office15\lync.exe [24370360 2018-04-10] (Microsoft Corporation)
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\...\Run: [DellSystemDetect] => C:\Users\sempe\AppData\Local\Apps\2.0\R90601MC.9EH\K6X73AJE.1E2\dell..tion_831211ca63b981c5_0008.0008_b150a6542eb950c1\DellSystemDetect.exe [314544 2017-09-29] (Dell)
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\...\MountPoints2: {c5134f04-7374-11e6-be6b-f48e38e8023b} - "D:\Setup.exe" /s
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\...\MountPoints2: {c5134f0d-7374-11e6-be6b-f48e38e8023b} - "D:\Setup.exe" /s
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [570880 2017-09-29] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Privoxy.lnk [2018-04-30]
ShortcutTarget: Privoxy.lnk -> C:\Program Files (x86)\Privoxy\privoxy.exe (The Privoxy team - www.privoxy.org)
Startup: C:\Users\sempe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2017-02-04]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\sempe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2017-06-03]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{24dda6c0-e4f1-4183-bddb-fbd498a33fc9}: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{741ac389-a61a-438e-af04-ceda25dc97c8}: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{aaaff37a-507a-4b8f-afbc-4bff7d7edbe0}: [DhcpNameServer] 192.168.254.254

Internet Explorer:
==================
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell15.msn.com/?pc=DCTE
HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE
SearchScopes: HKU\S-1-5-21-3205350201-1289876752-4104875119-1001 -> DefaultScope {2B3702D8-121C-4EF0-925F-D3ABD19DB50A} URL = 
SearchScopes: HKU\S-1-5-21-3205350201-1289876752-4104875119-1001 -> {2B3702D8-121C-4EF0-925F-D3ABD19DB50A} URL = 
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2018-02-15] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2017-08-24] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-01-24] (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-24] (Oracle Corporation)

Edge: 
======
Edge HomeButtonPage: HKU\S-1-5-21-3205350201-1289876752-4104875119-1001 -> hxxp://www.news.google.com/
Edge Extension: (Adblock Plus) -> 10_EyeoGmbHAdblockPlus_d55gg7py3s0m0 => C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.9.0_neutral__d55gg7py3s0m0 [2017-08-03]

FireFox:
========
FF DefaultProfile: wv9x2lo3.default-1519094877732
FF ProfilePath: C:\Users\sempe\AppData\Roaming\Mozilla\Firefox\Profiles\wv9x2lo3.default-1519094877732 [2018-05-17]
FF Homepage: Mozilla\Firefox\Profiles\wv9x2lo3.default-1519094877732 -> hxxps://news.google.com/
FF Extension: (Pinned GMail) - C:\Users\sempe\AppData\Roaming\Mozilla\Firefox\Profiles\wv9x2lo3.default-1519094877732\Extensions\gmail_panel@alejandrobrizuela.com.ar.xpi [2018-02-24]
FF Extension: (HTTPS Everywhere) - C:\Users\sempe\AppData\Roaming\Mozilla\Firefox\Profiles\wv9x2lo3.default-1519094877732\Extensions\https-everywhere@eff.org.xpi [2018-02-20]
FF Extension: (Avast Passwords) - C:\Users\sempe\AppData\Roaming\Mozilla\Firefox\Profiles\wv9x2lo3.default-1519094877732\Extensions\jid1-r1tDuNiNb4SEww@jetpack.xpi [2018-02-20]
FF Extension: (Google Translator for Firefox) - C:\Users\sempe\AppData\Roaming\Mozilla\Firefox\Profiles\wv9x2lo3.default-1519094877732\Extensions\translator@zoli.bod.xpi [2018-02-24]
FF Extension: (Adblock Plus) - C:\Users\sempe\AppData\Roaming\Mozilla\Firefox\Profiles\wv9x2lo3.default-1519094877732\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-02-24]
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-13] ()
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-12-09] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-13] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-08-25] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-08-25] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-24] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-02-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-04-01] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-03-24] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-03-24] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-05-11] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-12-09] (Adobe Systems)

Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://news.google.com/
CHR StartupUrls: Default -> "hxxp://news.google.com/"
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default [2018-05-17]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-09-29]
CHR Extension: (Touch VPN) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\bihmplhobchoageeokmgbdihknkjbknd [2018-05-10]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-09-29]
CHR Extension: (Avast Passwords) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2018-05-03]
CHR Extension: (HTTPS Everywhere) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2018-04-12]
CHR Extension: (AdBlock) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-05-10]
CHR Extension: (Google Calendar) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2018-04-06]
CHR Extension: (Eye Dropper) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka [2018-02-26]
CHR Extension: (Page Ruler) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlpkojjdgbllmedoapgfodplfhcbnbpn [2018-02-26]
CHR Extension: (Google Mail Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2017-09-29]
CHR Extension: (Google Hangouts) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2018-02-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-03-22]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-09-29]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-24]
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-05-17]
CHR Extension: (Docs) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-04]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2018-05-17]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-04]
CHR Extension: (Google Calendar) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-10-04]
CHR Extension: (Avast Passwords) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2018-05-17]
CHR Extension: (Google Docs Offline) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-04]
CHR Extension: (AdBlock) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-05-17]
CHR Extension: (Google Mail Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2017-10-04]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-17]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-04]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-17]
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2 [2018-05-17]
CHR Extension: (Slides) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-07]
CHR Extension: (Docs) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-07]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-07]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2018-05-17]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-07]
CHR Extension: (Adobe Acrobat) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-02-07]
CHR Extension: (Sheets) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-07]
CHR Extension: (HTTPS Everywhere) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2018-04-16]
CHR Extension: (Google Docs Offline) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-08]
CHR Extension: (AdBlock) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-05-10]
CHR Extension: (Google Calendar) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2018-04-16]
CHR Extension: (Eye Dropper) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka [2018-02-07]
CHR Extension: (Page Ruler) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\jlpkojjdgbllmedoapgfodplfhcbnbpn [2018-02-28]
CHR Extension: (Google Hangouts) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\knipolnnllmklapflnccelgolnpehhpl [2018-02-19]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-02-07]
CHR Extension: (Google Mail Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2018-02-07]
CHR Extension: (Google Hangouts) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2018-02-19]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-16]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-07]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-30]
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4 [2018-05-17]
CHR Extension: (Slides) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-13]
CHR Extension: (Docs) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-13]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-13]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-13]
CHR Extension: (Adobe Acrobat) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-02-13]
CHR Extension: (Sheets) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-13]
CHR Extension: (HTTPS Everywhere) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2018-05-17]
CHR Extension: (Google Docs Offline) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-03-29]
CHR Extension: (AdBlock) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-05-17]
CHR Extension: (Google Calendar) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2018-04-11]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-02-13]
CHR Extension: (Google Mail Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2018-02-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-13]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-17]
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5 [2018-05-17]
CHR Extension: (Slides) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-03-23]
CHR Extension: (SEOquake) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\akdgnmcogleenhbclghghlkkdndkjdjc [2018-05-01]
CHR Extension: (Docs) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-23]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-23]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-23]
CHR Extension: (NoFollow) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\dfogidghaigoomjdeacndafapdijmiid [2018-05-02]
CHR Extension: (gInfinity) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\dgomfdmdnjbnfhodggijhpbmkgfabcmn [2018-04-15]
CHR Extension: (Copy All Urls) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\djdmadneanknadilpjiknlnanaolmbfk [2018-05-12]
CHR Extension: (MozBar) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\eakacpaijcpapndcfffdgphdiccmpknp [2018-05-01]
CHR Extension: (Avast Passwords) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2018-05-04]
CHR Extension: (Serpstat Plugin) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\fcgbopaomlpldhbinhgebmkcnkfconmn [2018-05-16]
CHR Extension: (Sheets) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-03-23]
CHR Extension: (Automatic Backlink Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\fkllkmgclnabanhckclcipnddfbindan [2018-05-01]
CHR Extension: (HTTPS Everywhere) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2018-04-14]
CHR Extension: (Google Docs Offline) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-03-24]
CHR Extension: (AdBlock) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-05-11]
CHR Extension: (Keywords Everywhere - Keyword Tool) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\hbapdpeemoojbophdfndmlgdhppljgmp [2018-05-07]
CHR Extension: (Hunter) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\hgmhmanijnjhaffoampdlllchpolkdnj [2018-03-31]
CHR Extension: (Eye Dropper) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka [2018-03-23]
CHR Extension: (Page Ruler) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\jlpkojjdgbllmedoapgfodplfhcbnbpn [2018-03-23]
CHR Extension: (Google Mail Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2018-03-23]
CHR Extension: (Broken Link Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\nibppfobembgfmejpjaaeocbogeonhch [2018-04-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-03-23]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 5\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-27]
CHR Extension: (Ahrefs SEO Toolbar) - C:\Users\sempe\Downloads\ahrefs-chrome-toolbar [2018-03-23] [UpdateUrl: hxxps://ahrefs.com/] <==== ATTENTION
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6 [2018-05-17]
CHR Extension: (Slides) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-11]
CHR Extension: (Docs) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-11]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-05-11]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-11]
CHR Extension: (Sheets) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-11]
CHR Extension: (Google Docs Offline) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-11]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-05-11]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 6\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-11]
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7 [2018-05-17]
CHR Extension: (Slides) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-14]
CHR Extension: (Docs) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-14]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-05-14]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-14]
CHR Extension: (Sheets) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-14]
CHR Extension: (Google Docs Offline) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-15]
CHR Extension: (Google Mail Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2018-05-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-14]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-05-14]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 7\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-14]
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8 [2018-05-17]
CHR Extension: (Slides) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-14]
CHR Extension: (Docs) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-14]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-05-14]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-14]
CHR Extension: (Sheets) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-14]
CHR Extension: (Google Docs Offline) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-14]
CHR Extension: (Google Mail Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2018-05-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-14]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-05-14]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 8\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-14]
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9 [2018-05-17]
CHR Extension: (Slides) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-15]
CHR Extension: (Docs) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-15]
CHR Extension: (Google Drive) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-05-15]
CHR Extension: (Pop up blocker for Chrome™ - Poper Blocker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2018-05-15]
CHR Extension: (YouTube) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-15]
CHR Extension: (Sheets) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-15]
CHR Extension: (HTTPS Everywhere) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2018-05-15]
CHR Extension: (Google Docs Offline) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-17]
CHR Extension: (AdBlock) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-05-15]
CHR Extension: (Google Calendar) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2018-05-15]
CHR Extension: (Google Mail Checker) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2018-05-15]
CHR Extension: (Google Hangouts) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2018-05-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-15]
CHR Extension: (Gmail) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-05-15]
CHR Extension: (Chrome Media Router) - C:\Users\sempe\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-05-15]
CHR Profile: C:\Users\sempe\AppData\Local\Google\Chrome\User Data\System Profile [2018-05-17]
CHR HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3205350201-1289876752-4104875119-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2017-02-04] (Adobe Systems) [File not signed]
R2 AdobeActiveFileMonitor13.0; C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe [231120 2015-01-30] (Adobe Systems Incorporated)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [753240 2016-12-09] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7620096 2018-05-11] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [317280 2018-05-11] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [7002120 2017-12-21] ()
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [526888 2017-10-20] (EasyAntiCheat Ltd)
R2 esifsvc; C:\WINDOWS\System32\Intel\DPTF\esif_uf.exe [1585784 2016-06-03] (Intel Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144104 2015-07-09] (ELAN Microelectronics Corp.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18504 2016-04-28] (Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [515232 2017-06-22] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-20] (Intel Corporation) [File not signed]
S3 Intel(R) WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-06-24] (Intel Corporation)
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-20] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2015-10-16] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2017-04-10] ()
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4070736 2016-01-31] (INCA Internet Co., Ltd.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [523152 2018-03-14] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [523152 2018-03-14] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2119688 2016-12-31] (Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2180624 2016-12-31] (Electronic Arts)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-05-01] (arvato digital services llc)
S3 ptsysexec; C:\Windows\ptsysexec.exe [436320 2015-07-01] (Pismo Technic Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-05] (Realtek Semiconductor)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11293936 2018-04-03] (TeamViewer GmbH)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [613296 2015-12-22] (Waves Audio Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3750304 2017-04-10] (Intel® Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [196640 2018-05-11] (AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [227504 2018-03-03] (AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [199440 2018-03-03] (AVAST Software)
R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [343752 2018-03-03] (AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [57680 2018-03-03] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46968 2018-05-11] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [159120 2018-05-11] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111360 2018-05-11] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [85968 2018-05-11] (AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1027720 2018-05-11] (AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460520 2018-05-11] (AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [205976 2018-05-11] (AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [381552 2018-05-11] (AVAST Software)
S3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [32960 2017-07-27] (Dell Inc.)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [32568 2017-07-27] (Dell Computer Corporation)
R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [19440 2015-05-09] (OSR Open Systems Resources, Inc.)
R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [70208 2016-05-19] (Intel Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [65088 2016-05-19] (Intel Corporation)
R3 ElcMouLFlt; C:\WINDOWS\System32\drivers\ElcMouLFlt.sys [28648 2015-09-11] (ELECOM)
R3 ElcMouUFlt; C:\WINDOWS\System32\drivers\ElcMouUFlt.sys [27624 2015-09-11] (ELECOM)
R3 esif_lf; C:\WINDOWS\System32\drivers\esif_lf.sys [343608 2016-05-19] (Intel Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [76192 2018-03-19] ()
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [244720 2017-06-22] (Intel Corporation)
R0 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [193768 2018-03-31] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [112864 2018-05-17] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [44768 2018-05-17] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253664 2018-05-17] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [102112 2018-05-17] (Malwarebytes)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [29192 2016-03-17] (Marvell Semiconductor, Inc.)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7689728 2017-09-29] (Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmi.inf_amd64_b79991c48f5211ac\nvlddmkm.sys [17544792 2018-03-26] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [31632 2018-03-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [59240 2018-03-24] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [59272 2018-03-14] (NVIDIA Corporation)
S3 pfmfs_178; C:\WINDOWS\System32\Drivers\pfmfs_178.sys [320904 2015-07-01] (Pismo Technic Inc.)
R0 PxHlpa64; C:\WINDOWS\System32\drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [777944 2016-03-21] (Realsil Semiconductor Corporation)
S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2016-10-18] ()
R3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] ()
R3 vjoy; C:\WINDOWS\System32\drivers\vjoy.sys [57976 2017-04-06] (Shaul Eizikovich)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-05-17 20:12 - 2018-05-17 20:13 - 000049015 _____ C:\Users\sempe\Downloads\FRST.txt
2018-05-17 20:12 - 2018-05-17 20:12 - 000000000 ____D C:\Users\sempe\Downloads\FRST-OlderVersion
2018-05-17 20:11 - 2018-05-17 20:12 - 002413056 _____ (Farbar) C:\Users\sempe\Downloads\FRST64.exe
2018-05-17 20:11 - 2018-05-17 20:12 - 000000000 ____D C:\FRST
2018-05-17 20:01 - 2018-05-17 20:08 - 000000000 ____D C:\Users\sempe\Desktop\virus
2018-05-17 19:38 - 2018-05-17 20:03 - 000000000 ____D C:\AdwCleaner
2018-05-17 19:37 - 2018-05-17 19:37 - 007271632 _____ (Malwarebytes) C:\Users\sempe\Downloads\AdwCleaner.exe
2018-05-17 08:59 - 2018-05-17 08:59 - 000000000 ___HD C:\OneDriveTemp
2018-05-17 08:25 - 2018-05-17 08:25 - 000000000 _____ C:\Users\sempe\Desktop\serps ensures that the post is indexed.txt
2018-05-16 18:35 - 2018-05-16 18:35 - 000022031 _____ C:\Users\sempe\Desktop\simple-post-notes.1.7.1.zip
2018-05-13 10:16 - 2018-05-14 09:15 - 000000263 _____ C:\Users\sempe\Desktop\About Montly SEO IMPORTANT.txt
2018-05-12 19:48 - 2018-05-12 19:52 - 000000000 ____D C:\Users\sempe\Downloads\Beaver Builder
2018-05-12 09:13 - 2018-05-12 09:13 - 000006486 _____ C:\Users\sempe\Downloads\htaccess_Backup_for_www.seosemper.com.txt
2018-05-11 13:51 - 2018-05-11 13:51 - 000376536 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2018-05-11 06:56 - 2018-05-11 06:56 - 000000000 ____D C:\Users\sempe\Downloads\Bookmarks Backup
2018-05-10 16:08 - 2018-05-10 16:08 - 000001498 _____ C:\Users\sempe\Desktop\SEOSemper- Ahrefs Keywords - Shortcut.lnk
2018-05-10 08:37 - 2018-05-02 05:25 - 000835064 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-05-10 08:37 - 2018-05-02 05:25 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-05-09 18:27 - 2018-05-03 15:57 - 000599448 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-05-09 18:27 - 2018-05-03 15:43 - 000373664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2018-05-09 18:27 - 2018-05-03 15:37 - 000749984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-05-09 18:27 - 2018-05-03 15:37 - 000408992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-05-09 18:27 - 2018-05-03 14:31 - 002193688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-05-09 18:27 - 2018-05-03 14:18 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2018-05-09 18:27 - 2018-05-03 14:16 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe
2018-05-09 18:27 - 2018-05-03 14:16 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-05-09 18:27 - 2018-05-03 14:16 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2018-05-09 18:27 - 2018-05-03 14:12 - 000816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-05-09 18:27 - 2018-05-03 14:09 - 003405824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-05-09 18:27 - 2018-05-03 14:07 - 001822720 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-05-09 18:27 - 2018-05-03 14:00 - 002902528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-05-09 18:27 - 2018-05-03 14:00 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcSpecfc.dll
2018-05-09 18:27 - 2018-05-03 14:00 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2018-05-09 18:27 - 2018-05-03 13:59 - 018924544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-05-09 18:27 - 2018-05-03 13:58 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-05-09 18:27 - 2018-05-03 13:57 - 019354624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-05-09 18:27 - 2018-05-03 13:57 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-05-09 18:27 - 2018-05-03 13:57 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-05-09 18:27 - 2018-05-03 13:56 - 002677248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-05-09 18:27 - 2018-05-03 13:56 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2018-05-09 18:27 - 2018-05-03 13:55 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-05-09 18:27 - 2018-05-03 13:54 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-05-09 18:27 - 2018-05-03 13:53 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-05-09 18:27 - 2018-05-03 13:52 - 003662848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-05-09 18:27 - 2018-05-03 13:52 - 000664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-05-09 18:27 - 2018-05-03 13:52 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-05-09 18:27 - 2018-05-03 13:51 - 001560064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-05-09 18:27 - 2018-05-03 13:48 - 000328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ninput.dll
2018-05-09 18:27 - 2018-04-16 06:04 - 000779952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2018-05-09 18:27 - 2018-04-16 05:49 - 001954056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-05-09 18:27 - 2018-04-16 05:49 - 000382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2018-05-09 18:27 - 2018-04-16 05:47 - 000398744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2018-05-09 18:27 - 2018-04-16 05:33 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-05-09 18:27 - 2018-04-16 05:26 - 007384576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-05-09 18:27 - 2018-04-16 05:25 - 001430768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2018-05-09 18:27 - 2018-04-16 04:47 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-05-09 18:27 - 2018-04-16 04:47 - 001433360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-05-09 18:27 - 2018-04-16 04:47 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2018-05-09 18:27 - 2018-04-16 04:47 - 000311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2018-05-09 18:27 - 2018-04-16 04:38 - 001123464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-05-09 18:27 - 2018-04-16 04:14 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2018-05-09 18:27 - 2018-04-16 04:14 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2018-05-09 18:27 - 2018-04-16 04:14 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2018-05-09 18:27 - 2018-04-16 04:12 - 017160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-05-09 18:27 - 2018-04-16 04:12 - 013704704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-05-09 18:27 - 2018-04-16 04:12 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-05-09 18:27 - 2018-04-16 04:08 - 003181568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-05-09 18:27 - 2018-04-16 04:08 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2018-05-09 18:27 - 2018-04-16 04:07 - 005195776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-05-09 18:27 - 2018-04-16 04:07 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2018-05-09 18:27 - 2018-04-16 04:07 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2018-05-09 18:27 - 2018-04-16 04:06 - 011924480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-05-09 18:27 - 2018-04-16 04:06 - 000377856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2018-05-09 18:27 - 2018-04-16 04:05 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2018-05-09 18:27 - 2018-04-16 04:04 - 002523136 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2018-05-09 18:27 - 2018-04-16 04:04 - 001342464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wpc.dll
2018-05-09 18:27 - 2018-04-16 04:04 - 000982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2018-05-09 18:27 - 2018-04-16 04:03 - 002628608 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-05-09 18:27 - 2018-04-16 04:03 - 002413568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2018-05-09 18:27 - 2018-04-16 04:03 - 000826880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2018-05-09 18:27 - 2018-04-16 04:02 - 001669120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2018-05-09 18:26 - 2018-05-03 15:51 - 001056152 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-05-09 18:26 - 2018-05-03 15:50 - 001206688 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-05-09 18:26 - 2018-05-03 15:48 - 002002336 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2018-05-09 18:26 - 2018-05-03 15:48 - 000077216 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-05-09 18:26 - 2018-05-03 15:47 - 008600472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-05-09 18:26 - 2018-05-03 15:45 - 002395040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-05-09 18:26 - 2018-05-03 15:38 - 002574240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-05-09 18:26 - 2018-05-03 15:36 - 007675792 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-05-09 18:26 - 2018-05-03 15:36 - 002710736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-05-09 18:26 - 2018-05-03 15:36 - 000437664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2018-05-09 18:26 - 2018-05-03 15:36 - 000247200 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-05-09 18:26 - 2018-05-03 15:35 - 000358496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2018-05-09 18:26 - 2018-05-03 15:34 - 021356824 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-05-09 18:26 - 2018-05-03 15:34 - 000070864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2018-05-09 18:26 - 2018-05-03 15:32 - 001054280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-05-09 18:26 - 2018-05-03 14:36 - 025254400 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-05-09 18:26 - 2018-05-03 14:31 - 006092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-05-09 18:26 - 2018-05-03 14:29 - 000285144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2018-05-09 18:26 - 2018-05-03 14:28 - 000061024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2018-05-09 18:26 - 2018-05-03 14:26 - 001057824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-05-09 18:26 - 2018-05-03 14:25 - 020290248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-05-09 18:26 - 2018-05-03 14:19 - 003663360 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-05-09 18:26 - 2018-05-03 14:18 - 000206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2018-05-09 18:26 - 2018-05-03 14:18 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcSpecfc.dll
2018-05-09 18:26 - 2018-05-03 14:17 - 007545344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2018-05-09 18:26 - 2018-05-03 14:16 - 023674880 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-05-09 18:26 - 2018-05-03 14:16 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-05-09 18:26 - 2018-05-03 14:16 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-05-09 18:26 - 2018-05-03 14:16 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-05-09 18:26 - 2018-05-03 14:15 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-05-09 18:26 - 2018-05-03 14:15 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\imgutil.dll
2018-05-09 18:26 - 2018-05-03 14:14 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-05-09 18:26 - 2018-05-03 14:14 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-05-09 18:26 - 2018-05-03 14:13 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-05-09 18:26 - 2018-05-03 14:12 - 000672768 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-05-09 18:26 - 2018-05-03 14:12 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-05-09 18:26 - 2018-05-03 14:11 - 000595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-05-09 18:26 - 2018-05-03 14:09 - 008068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-05-09 18:26 - 2018-05-03 14:09 - 004723712 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-05-09 18:26 - 2018-05-03 14:09 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-05-09 18:26 - 2018-05-03 14:09 - 002784256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-05-09 18:26 - 2018-05-03 14:09 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-05-09 18:26 - 2018-05-03 14:09 - 001548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-05-09 18:26 - 2018-05-03 14:08 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-05-09 18:26 - 2018-05-03 14:08 - 000808960 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-05-09 18:26 - 2018-05-03 14:05 - 000389120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ninput.dll
2018-05-09 18:26 - 2018-05-03 14:04 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2018-05-09 18:26 - 2018-05-03 14:03 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2018-05-09 18:26 - 2018-05-03 14:02 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2018-05-09 18:26 - 2018-05-03 13:58 - 006467072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2018-05-09 18:26 - 2018-05-03 13:57 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-05-09 18:26 - 2018-05-03 13:56 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-05-09 18:26 - 2018-05-03 13:53 - 006060544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-05-09 18:26 - 2018-05-03 13:51 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-05-09 18:26 - 2018-05-03 13:50 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-05-09 18:26 - 2018-04-16 06:07 - 001463344 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2018-05-09 18:26 - 2018-04-16 06:03 - 000128408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2018-05-09 18:26 - 2018-04-16 05:57 - 000279968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2018-05-09 18:26 - 2018-04-16 05:51 - 002513920 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-05-09 18:26 - 2018-04-16 05:50 - 001925760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2018-05-09 18:26 - 2018-04-16 05:48 - 005859248 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2018-05-09 18:26 - 2018-04-16 05:48 - 001638424 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-05-09 18:26 - 2018-04-16 05:38 - 000979360 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2018-05-09 18:26 - 2018-04-16 05:34 - 000230304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2018-05-09 18:26 - 2018-04-16 05:32 - 003904296 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-05-09 18:26 - 2018-04-16 05:32 - 001416392 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-05-09 18:26 - 2018-04-16 05:29 - 001779936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-05-09 18:26 - 2018-04-16 05:23 - 001101208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-05-09 18:26 - 2018-04-16 04:47 - 001929712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-05-09 18:26 - 2018-04-16 04:47 - 001490856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2018-05-09 18:26 - 2018-04-16 04:47 - 001323336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2018-05-09 18:26 - 2018-04-16 04:38 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-05-09 18:26 - 2018-04-16 04:37 - 000747416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2018-05-09 18:26 - 2018-04-16 04:34 - 006482664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-05-09 18:26 - 2018-04-16 04:34 - 001524776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-05-09 18:26 - 2018-04-16 04:16 - 003995136 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2018-05-09 18:26 - 2018-04-16 04:15 - 003490816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2018-05-09 18:26 - 2018-04-16 04:14 - 000250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2018-05-09 18:26 - 2018-04-16 04:14 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2018-05-09 18:26 - 2018-04-16 04:13 - 002890240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2018-05-09 18:26 - 2018-04-16 04:10 - 001498112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-05-09 18:26 - 2018-04-16 04:10 - 000371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-05-09 18:26 - 2018-04-16 04:10 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2018-05-09 18:26 - 2018-04-16 04:10 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2018-05-09 18:26 - 2018-04-16 04:09 - 000153600 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll
2018-05-09 18:26 - 2018-04-16 04:08 - 006576128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-05-09 18:26 - 2018-04-16 04:08 - 000859648 _____ (Microsoft Corporation) C:\WINDOWS\system32\appwiz.cpl
2018-05-09 18:26 - 2018-04-16 04:08 - 000181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\twext.dll
2018-05-09 18:26 - 2018-04-16 04:08 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingMonitor.dll
2018-05-09 18:26 - 2018-04-16 04:07 - 012689920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-05-09 18:26 - 2018-04-16 04:07 - 008031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-05-09 18:26 - 2018-04-16 04:07 - 003367936 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2018-05-09 18:26 - 2018-04-16 04:07 - 000792064 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2018-05-09 18:26 - 2018-04-16 04:07 - 000598528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-05-09 18:26 - 2018-04-16 04:07 - 000386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-05-09 18:26 - 2018-04-16 04:07 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2018-05-09 18:26 - 2018-04-16 04:07 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twext.dll
2018-05-09 18:26 - 2018-04-16 04:06 - 013660672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-05-09 18:26 - 2018-04-16 04:06 - 000820224 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2018-05-09 18:26 - 2018-04-16 04:06 - 000721920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-05-09 18:26 - 2018-04-16 04:06 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2018-05-09 18:26 - 2018-04-16 04:05 - 004113408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-05-09 18:26 - 2018-04-16 04:05 - 000863744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2018-05-09 18:26 - 2018-04-16 04:05 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 012833280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 002464768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 001236480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 000884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 000621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hgcpl.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 000556544 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2018-05-09 18:26 - 2018-04-16 04:04 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.immersiveshell.serviceprovider.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 004772352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 004385280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 004248064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 003287040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncCenter.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 002976256 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 002857984 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 002814976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 002741248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 000920064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2018-05-09 18:26 - 2018-04-16 04:03 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 000508928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 000402432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 000383488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2018-05-09 18:26 - 2018-04-16 04:03 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingMonitor.dll
2018-05-09 18:26 - 2018-04-16 04:02 - 004814336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-05-09 18:26 - 2018-04-16 04:02 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2018-05-09 18:26 - 2018-04-16 04:02 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-05-09 18:26 - 2018-04-16 04:01 - 001509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2018-05-09 18:26 - 2018-04-16 04:00 - 001739264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2018-05-09 18:26 - 2018-04-16 04:00 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-05-09 18:25 - 2018-05-03 15:56 - 001092016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-05-09 18:25 - 2018-05-03 15:56 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-05-09 18:25 - 2018-05-03 15:54 - 000748448 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2018-05-09 18:25 - 2018-05-03 15:54 - 000608160 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2018-05-09 18:25 - 2018-05-03 15:53 - 000461216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-05-09 18:25 - 2018-05-03 15:52 - 001568160 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2018-05-09 18:25 - 2018-05-03 15:52 - 001415296 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-05-09 18:25 - 2018-05-03 15:52 - 000137112 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2018-05-09 18:25 - 2018-05-03 15:50 - 000664992 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2018-05-09 18:25 - 2018-05-03 15:50 - 000423328 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2018-05-09 18:25 - 2018-05-03 15:50 - 000069536 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2018-05-09 18:25 - 2018-05-03 15:49 - 000035232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2018-05-09 18:25 - 2018-05-03 15:48 - 000272288 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2018-05-09 18:25 - 2018-05-03 15:47 - 001209760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-05-09 18:25 - 2018-05-03 15:45 - 000711936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-05-09 18:25 - 2018-05-03 15:41 - 000540064 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-05-09 18:25 - 2018-05-03 15:35 - 002472864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-05-09 18:25 - 2018-05-03 14:19 - 001300992 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-05-09 18:25 - 2018-05-03 14:19 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-05-09 18:25 - 2018-05-03 14:18 - 000400896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2018-05-09 18:25 - 2018-04-16 05:38 - 003180720 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2018-05-09 18:25 - 2018-04-16 05:30 - 002268024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2018-05-09 18:25 - 2018-04-16 05:28 - 000688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-05-09 18:25 - 2018-04-16 05:26 - 002711176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2018-05-09 18:25 - 2018-04-16 05:26 - 001506200 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2018-05-09 18:25 - 2018-04-16 04:36 - 000543920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-05-09 18:25 - 2018-04-16 04:35 - 002462704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2018-05-09 18:25 - 2018-04-16 04:34 - 001456104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2018-05-09 18:25 - 2018-04-16 04:34 - 001017048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-05-09 18:25 - 2018-04-16 04:14 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2018-05-09 18:25 - 2018-04-16 04:14 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUpdateAgent.dll
2018-05-09 18:25 - 2018-04-16 04:11 - 000531456 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-05-09 18:25 - 2018-04-16 04:09 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_User.dll
2018-05-09 18:25 - 2018-04-16 04:07 - 001495552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-05-09 18:25 - 2018-04-16 04:07 - 001425408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-05-09 18:25 - 2018-04-16 04:07 - 000837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-05-09 18:25 - 2018-04-16 04:07 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2018-05-09 18:25 - 2018-04-16 04:07 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2018-05-09 18:25 - 2018-04-16 04:05 - 000526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2018-05-09 18:25 - 2018-04-16 04:04 - 002490880 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2018-05-09 18:25 - 2018-04-16 04:04 - 002209280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-05-09 18:25 - 2018-04-16 04:04 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2018-05-09 18:25 - 2018-04-16 04:04 - 000648704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserLanguagesCpl.dll
2018-05-09 18:25 - 2018-04-16 04:04 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserLanguagesCpl.dll
2018-05-09 18:25 - 2018-04-16 04:03 - 003177472 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-05-09 18:25 - 2018-04-16 04:03 - 002462208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themecpl.dll
2018-05-09 18:25 - 2018-04-16 04:03 - 001353728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2018-05-09 18:25 - 2018-04-16 04:00 - 002223616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-05-09 18:25 - 2018-04-16 03:58 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2018-05-09 18:24 - 2018-05-03 15:53 - 000300448 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-05-09 18:24 - 2018-05-03 15:48 - 000793960 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2018-05-09 18:24 - 2018-05-03 15:43 - 000702568 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2018-05-09 18:24 - 2018-05-03 14:44 - 000595448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2018-05-09 18:24 - 2018-05-03 14:43 - 000594056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2018-05-09 18:24 - 2018-05-03 14:39 - 000212896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2018-05-09 18:24 - 2018-05-03 14:16 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadauthhelper.dll
2018-05-09 18:24 - 2018-05-03 14:16 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-05-09 18:24 - 2018-05-03 14:16 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2018-05-09 18:24 - 2018-05-03 14:15 - 000194048 _____ (Microsoft Corporation) C:\WINDOWS\system32\itircl.dll
2018-05-09 18:24 - 2018-05-03 14:14 - 000623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2018-05-09 18:24 - 2018-05-03 14:13 - 000253440 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2018-05-09 18:24 - 2018-05-03 14:12 - 000657408 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2018-05-09 18:24 - 2018-05-03 14:09 - 008432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-05-09 18:24 - 2018-05-03 14:09 - 001856000 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-05-09 18:24 - 2018-05-03 14:09 - 001344000 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2018-05-09 18:24 - 2018-05-03 14:06 - 003630080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2018-05-09 18:24 - 2018-05-03 14:05 - 001717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2018-05-09 18:24 - 2018-05-03 14:05 - 000483840 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2018-05-09 18:24 - 2018-05-03 14:03 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2018-05-09 18:24 - 2018-05-03 14:03 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2018-05-09 18:24 - 2018-05-03 13:57 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itircl.dll
2018-05-09 18:24 - 2018-05-03 13:57 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadauthhelper.dll
2018-05-09 18:24 - 2018-05-03 13:57 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-05-09 18:24 - 2018-05-03 13:53 - 007813120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-05-09 18:24 - 2018-05-03 13:53 - 000540672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2018-05-09 18:24 - 2018-05-03 13:50 - 001587712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-05-09 18:24 - 2018-05-03 13:49 - 003430400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2018-05-09 18:24 - 2018-05-03 13:48 - 001353728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2018-05-09 18:24 - 2018-05-03 13:48 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2018-05-09 18:24 - 2018-05-03 13:47 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2018-05-09 18:24 - 2018-04-16 05:49 - 000563632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2018-05-09 18:24 - 2018-04-16 05:33 - 001269616 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2018-05-09 18:24 - 2018-04-16 05:29 - 001873944 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2018-05-09 18:24 - 2018-04-16 05:29 - 000198440 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe
2018-05-09 18:24 - 2018-04-16 05:25 - 000661920 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2018-05-09 18:24 - 2018-04-16 05:25 - 000327008 _____ (Microsoft Corporation) C:\WINDOWS\system32\shlwapi.dll
2018-05-09 18:24 - 2018-04-16 05:25 - 000092032 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudNotifications.exe
2018-05-09 18:24 - 2018-04-16 05:24 - 000063656 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2018-05-09 18:24 - 2018-04-16 04:38 - 000444280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2018-05-09 18:24 - 2018-04-16 04:36 - 002386832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2018-05-09 18:24 - 2018-04-16 04:36 - 001575896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2018-05-09 18:24 - 2018-04-16 04:36 - 000832648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2018-05-09 18:24 - 2018-04-16 04:34 - 000572312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2018-05-09 18:24 - 2018-04-16 04:34 - 000279472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shlwapi.dll
2018-05-09 18:24 - 2018-04-16 04:34 - 000166408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe
2018-05-09 18:24 - 2018-04-16 04:34 - 000077552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudNotifications.exe
2018-05-09 18:24 - 2018-04-16 04:34 - 000052248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2018-05-09 18:24 - 2018-04-16 04:15 - 000674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockController.dll
2018-05-09 18:24 - 2018-04-16 04:14 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2018-05-09 18:24 - 2018-04-16 04:14 - 000101888 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProv2faHelper.dll
2018-05-09 18:24 - 2018-04-16 04:14 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProv2faHelper.dll
2018-05-09 18:24 - 2018-04-16 04:13 - 000084992 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2018-05-09 18:24 - 2018-04-16 04:12 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2018-05-09 18:24 - 2018-04-16 04:12 - 000126976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2018-05-09 18:24 - 2018-04-16 04:11 - 000301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2018-05-09 18:24 - 2018-04-16 04:11 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2018-05-09 18:24 - 2018-04-16 04:11 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2018-05-09 18:24 - 2018-04-16 04:11 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll
2018-05-09 18:24 - 2018-04-16 04:11 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2018-05-09 18:24 - 2018-04-16 04:11 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\eShims.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 001576960 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 000571904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 000225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 000220672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountWAMExtension.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 000218112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 000192000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2018-05-09 18:24 - 2018-04-16 04:10 - 000074240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncPolicy.dll
2018-05-09 18:24 - 2018-04-16 04:09 - 000408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2018-05-09 18:24 - 2018-04-16 04:09 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2018-05-09 18:24 - 2018-04-16 04:09 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncPolicy.dll
2018-05-09 18:24 - 2018-04-16 04:09 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000583680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.Schema.Shell.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2018-05-09 18:24 - 2018-04-16 04:08 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000406016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000319488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll
2018-05-09 18:24 - 2018-04-16 04:07 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2018-05-09 18:24 - 2018-04-16 04:06 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2018-05-09 18:24 - 2018-04-16 04:06 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2018-05-09 18:24 - 2018-04-16 04:06 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2018-05-09 18:24 - 2018-04-16 04:05 - 000626176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2018-05-09 18:24 - 2018-04-16 04:05 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2018-05-09 18:24 - 2018-04-16 04:04 - 000997376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2018-05-09 18:24 - 2018-04-16 04:04 - 000976896 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2018-05-09 18:24 - 2018-04-16 04:03 - 001224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2018-05-09 18:24 - 2018-04-16 04:03 - 000825856 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2018-05-09 18:24 - 2018-04-16 04:03 - 000697344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2018-05-09 18:24 - 2018-04-16 04:02 - 000440832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2018-05-09 18:24 - 2018-04-16 04:01 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2018-05-09 18:24 - 2018-04-16 04:01 - 000518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2018-05-09 18:24 - 2018-04-16 04:01 - 000366592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Geolocation.dll
2018-05-09 18:24 - 2018-04-16 04:01 - 000194560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2018-05-09 18:24 - 2018-04-16 04:01 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe
2018-05-09 18:24 - 2018-04-16 04:00 - 000682496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2018-05-09 18:24 - 2018-04-16 04:00 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2018-05-09 18:24 - 2018-04-16 04:00 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2018-05-09 18:24 - 2018-04-16 04:00 - 000356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2018-05-09 18:24 - 2018-04-16 04:00 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2018-05-09 18:24 - 2018-04-16 04:00 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2018-05-09 18:24 - 2018-04-16 04:00 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2018-05-09 18:24 - 2018-04-16 04:00 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe
2018-05-09 18:24 - 2018-04-16 03:59 - 001332736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2018-05-09 18:24 - 2018-04-16 03:59 - 000971264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2018-05-09 18:24 - 2018-04-16 03:58 - 001472000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2018-05-09 18:24 - 2017-11-26 21:26 - 000048112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2018-05-07 18:08 - 2018-05-17 18:41 - 000000000 ____D C:\Users\sempe\Desktop\Blogging For Business Course
2018-05-05 18:39 - 2018-05-05 18:39 - 000001002 _____ C:\Users\sempe\Desktop\ScrapeBox - Shortcut.lnk
2018-05-05 17:53 - 2018-05-05 17:53 - 000002866 _____ C:\Users\sempe\Desktop\PAM'SADPOSTINGSOFTWARE_GUIDE - Shortcut.lnk
2018-05-05 17:53 - 2018-05-05 17:53 - 000002711 _____ C:\Users\sempe\Desktop\Tutorial link - Shortcut.lnk
2018-05-05 17:51 - 2018-05-05 17:52 - 000000000 ____D C:\PAM's Auto Ad Posting Software1.1ver
2018-05-05 17:51 - 2018-05-05 17:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PAM's Auto Ad Posting Software1.1ver
2018-05-05 17:46 - 2018-05-05 17:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TwitterBlasterPro
2018-05-05 17:46 - 2018-05-05 17:46 - 000000000 ____D C:\Program Files (x86)\TwitterBlasterPro
2018-05-05 17:45 - 2018-05-05 17:45 - 000001062 _____ C:\Users\sempe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ScrapeBox.lnk
2018-05-05 17:44 - 2018-05-05 17:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Power Indexer Pro
2018-05-05 17:44 - 2018-05-05 17:44 - 000000000 ____D C:\ProgramData\InstallMate
2018-05-05 17:44 - 2018-05-05 17:44 - 000000000 ____D C:\Program Files (x86)\PowerIndexerPro
2018-05-05 17:42 - 2018-05-05 17:42 - 000001192 _____ C:\Users\sempe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PinPal Bot.lnk
2018-05-05 17:42 - 2018-05-05 17:42 - 000000000 ____D C:\Users\sempe\AppData\Local\PinPalBot
2018-05-05 17:40 - 2018-05-05 17:40 - 000001301 _____ C:\Users\sempe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Pro Email Extractor v1.lnk
2018-05-05 17:33 - 2018-05-05 17:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Instant Video Articles
2018-05-05 17:32 - 2018-05-05 17:32 - 000001625 _____ C:\Users\sempe\Desktop\Video Tutorial - Shortcut.lnk
2018-05-05 17:30 - 2018-05-05 17:31 - 000000000 ____D C:\Program Files (x86)\HotItemFinder
2018-05-05 17:30 - 2018-05-05 17:30 - 000002012 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hotitemfinder.lnk
2018-05-05 17:30 - 2018-05-05 17:30 - 000002006 _____ C:\ProgramData\Microsoft\Windows\Start Menu\hotitemfinder.lnk
2018-05-05 17:30 - 2018-05-05 17:30 - 000000000 ____D C:\WINDOWS\Hot Item Finder
2018-05-05 17:30 - 2018-05-05 17:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hot Item Finder
2018-05-05 17:28 - 2018-05-05 17:30 - 000000000 ____D C:\Program Files (x86)\FBP - Facebook Blaster Pro
2018-05-05 17:28 - 2018-05-05 17:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FBP - Facebook Blaster Pro
2018-05-05 17:21 - 2018-05-11 17:32 - 000000000 ____D C:\Program Files (x86)\Spin Master Pro
2018-05-05 17:21 - 2018-05-05 17:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spin Master Pro
2018-05-05 16:22 - 2018-05-05 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backlink Power Indexer
2018-05-05 16:22 - 2018-05-05 16:22 - 000000000 ____D C:\Program Files (x86)\My SEO Search Engine Optimization
2018-05-05 09:41 - 2018-05-05 09:41 - 000001666 _____ C:\Users\sempe\Desktop\seo-in-practice - Shortcut.lnk
2018-05-04 10:08 - 2018-05-04 10:08 - 000002352 _____ C:\Users\sempe\Desktop\Guest Blogging Template - Shortcut.lnk
2018-05-03 20:49 - 2018-05-03 20:49 - 007924192 _____ (Tim Kosse) C:\Users\sempe\Downloads\FileZilla_3.32.0_win64-setup.exe
2018-05-03 19:28 - 2018-05-03 19:28 - 000002249 _____ C:\Users\sempe\Desktop\link exchange - Shortcut.lnk
2018-05-02 19:27 - 2018-05-02 19:27 - 000002366 _____ C:\Users\sempe\Desktop\broken link building guide - Shortcut.lnk
2018-05-02 16:09 - 2018-05-02 16:09 - 000002393 _____ C:\Users\sempe\Desktop\White Hat Link Building SEOPS - Shortcut.lnk
2018-05-02 15:43 - 2018-05-05 17:39 - 000000000 ____D C:\Users\sempe\Desktop\Best SEO Pack
2018-05-02 15:42 - 2018-05-02 15:42 - 000001577 _____ C:\Users\sempe\Desktop\SEO PowerSuite Saves - Shortcut.lnk
2018-05-02 15:41 - 2018-05-02 15:41 - 000001577 _____ C:\Users\sempe\Documents\SEO PowerSuite Saves - Shortcut.lnk
2018-05-02 15:37 - 2018-05-02 15:39 - 126237340 _____ C:\Users\sempe\Downloads\Best SEO Pack.zip
2018-05-02 15:36 - 2018-05-02 15:36 - 000001310 _____ C:\Users\sempe\Desktop\Help Files - Shortcut.lnk
2018-05-02 15:19 - 2018-05-02 15:19 - 000000000 ____D C:\Users\sempe\AppData\Local\TeamViewer
2018-05-01 14:27 - 2018-05-01 14:27 - 000002484 _____ C:\Users\sempe\Desktop\Link Building  Email Templates - Shortcut.lnk
2018-04-30 07:32 - 2018-05-05 10:30 - 000009816 _____ C:\Users\sempe\.buzzbundle.properties
2018-04-30 07:31 - 2018-05-05 10:30 - 000000000 ____D C:\Users\sempe\.buzzbundle
2018-04-30 07:16 - 2018-04-30 07:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Privoxy
2018-04-30 07:16 - 2018-04-30 07:16 - 000000000 ____D C:\Program Files (x86)\Privoxy
2018-04-30 07:13 - 2018-04-30 07:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Link-AssistantCom
2018-04-30 07:13 - 2018-04-30 07:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BuzzBundle
2018-04-30 07:12 - 2018-04-30 07:13 - 000000000 ____D C:\Program Files (x86)\Link-AssistantCom
2018-04-30 07:03 - 2018-04-30 07:15 - 000000000 ____D C:\Users\sempe\Downloads\SEO Power Suite
2018-04-29 15:31 - 2018-04-30 14:28 - 000001426 _____ C:\Users\sempe\Desktop\Associate Degree's - Shortcut.lnk
2018-04-29 08:56 - 2018-05-17 18:18 - 000000325 _____ C:\Users\sempe\.seopowersuite.properties
2018-04-29 08:42 - 2018-05-17 20:05 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-04-29 08:42 - 2018-05-03 10:36 - 000000000 ____D C:\Users\sempe\AppData\Roaming\TeamViewer
2018-04-29 08:42 - 2018-04-29 08:42 - 000001078 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 13.lnk
2018-04-28 12:19 - 2018-04-30 14:28 - 000001737 _____ C:\Users\sempe\Desktop\Concrete Pipe Machines - Shortcut.lnk
2018-04-28 11:28 - 2018-04-28 11:28 - 000000000 ____D C:\ProgramData\PointBridge, LLC
2018-04-28 11:05 - 2018-04-30 14:28 - 000002343 _____ C:\Users\sempe\Desktop\Broken Link Building Template - Shortcut.lnk
2018-04-28 10:50 - 2018-04-28 10:56 - 000000000 ____D C:\Users\sempe\AppData\Local\Netpeak Software
2018-04-28 10:50 - 2018-04-28 10:55 - 000000000 ____D C:\Users\sempe\AppData\Roaming\Netpeak Software
2018-04-28 10:34 - 2018-04-28 10:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xenu's Link Sleuth
2018-04-28 10:34 - 2018-04-28 10:34 - 000000000 ____D C:\Program Files (x86)\Xenu
2018-04-28 08:19 - 2018-04-28 08:19 - 000000000 ____D C:\Users\sempe\AppData\Roaming\aStonish
2018-04-28 08:18 - 2018-04-28 08:18 - 000000000 ____D C:\ProgramData\aStonish
2018-04-28 08:14 - 2018-04-28 08:14 - 000110712 _____ C:\Users\sempe\Documents\Report.csv
2018-04-28 07:59 - 2018-04-28 07:59 - 000000000 ____D C:\Users\sempe\AppData\Roaming\BeamUsUp
2018-04-19 20:23 - 2018-04-19 20:23 - 000000000 ____D C:\Program Files\OPPO
2018-04-19 17:05 - 2018-05-17 15:17 - 000003398 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-19 17:05 - 2018-05-17 15:17 - 000003176 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-19 17:05 - 2018-05-17 15:17 - 000003140 _____ C:\WINDOWS\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-19 17:05 - 2018-05-17 15:17 - 000002984 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-19 17:05 - 2018-05-17 15:17 - 000002956 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-19 17:05 - 2018-05-17 15:17 - 000002914 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-19 17:05 - 2018-05-17 15:17 - 000002838 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-19 17:05 - 2018-05-17 15:17 - 000002744 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2018-04-19 17:05 - 2018-04-19 17:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-04-19 17:05 - 2018-03-14 21:01 - 002480520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2018-04-19 17:05 - 2018-03-14 21:01 - 002137488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2018-04-19 17:05 - 2018-03-14 21:01 - 001310608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvRtmpStreamer64.dll
2018-04-19 17:04 - 2018-03-24 07:05 - 000138120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2018-04-19 17:04 - 2018-03-05 14:18 - 000189784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2018-04-19 17:04 - 2018-03-05 14:18 - 000152408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2018-04-19 17:03 - 2018-04-19 17:03 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2018-04-19 17:01 - 2018-03-26 00:15 - 000998424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2018-04-19 17:01 - 2018-03-26 00:15 - 000950016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2018-04-19 17:01 - 2018-03-26 00:15 - 000625504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2018-04-19 17:01 - 2018-03-26 00:15 - 000516024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2018-04-19 17:01 - 2018-03-26 00:14 - 004318112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2018-04-19 17:01 - 2018-03-26 00:14 - 003719096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2018-04-19 17:01 - 2018-03-26 00:14 - 001985112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6439135.dll
2018-04-19 17:01 - 2018-03-26 00:14 - 001683712 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6439135.dll
2018-04-19 17:01 - 2018-03-26 00:14 - 001138720 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2018-04-19 17:01 - 2018-03-26 00:14 - 001065888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2018-04-19 17:01 - 2018-03-26 00:13 - 040278608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2018-04-19 17:01 - 2018-03-26 00:13 - 035188992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2018-04-19 17:01 - 2018-03-26 00:10 - 013571520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2018-04-19 17:01 - 2018-03-26 00:10 - 011132384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2018-04-19 17:01 - 2018-03-26 00:09 - 019855144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2018-04-19 17:01 - 2018-03-26 00:09 - 016496776 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2018-04-19 17:01 - 2018-03-26 00:09 - 001346128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2018-04-19 17:01 - 2018-03-26 00:09 - 001153744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2018-04-19 17:01 - 2018-03-26 00:09 - 001061352 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2018-04-19 17:01 - 2018-03-26 00:09 - 000902096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2018-04-19 17:01 - 2018-03-26 00:09 - 000811808 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2018-04-19 17:01 - 2018-03-26 00:09 - 000650232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2018-04-19 17:01 - 2018-03-26 00:08 - 012967056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2018-04-19 17:01 - 2018-03-26 00:08 - 011001504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2018-04-19 17:01 - 2018-03-26 00:08 - 004633920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2018-04-19 17:01 - 2018-03-26 00:08 - 003939624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2018-04-19 17:01 - 2018-03-24 09:19 - 000059240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2018-04-19 17:01 - 2018-03-14 21:01 - 000059272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2018-04-19 16:52 - 2018-03-24 07:02 - 005952392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2018-04-19 16:52 - 2018-03-24 07:02 - 002596320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2018-04-19 16:52 - 2018-03-24 07:02 - 001767824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2018-04-19 16:52 - 2018-03-24 07:02 - 000633224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2018-04-19 16:52 - 2018-03-24 07:02 - 000451040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2018-04-19 16:52 - 2018-03-24 07:02 - 000123840 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2018-04-19 16:52 - 2018-03-24 07:02 - 000083072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2018-04-19 16:52 - 2018-03-21 19:22 - 008114212 _____ C:\WINDOWS\system32\nvcoproc.bin
2018-04-19 16:52 - 2018-03-05 14:34 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2018-04-18 13:51 - 2018-04-18 13:51 - 000065972 _____ C:\Users\sempe\Desktop\Globe_bill.pdf
2018-04-17 20:54 - 2018-04-17 20:54 - 000001379 _____ C:\Users\sempe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Screaming Frog SEO Spider.lnk
2018-04-17 20:54 - 2018-04-17 20:54 - 000001236 _____ C:\Users\sempe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Uninstall Screaming Frog SEO Spider.lnk
2018-04-17 20:54 - 2018-04-17 20:54 - 000000000 ____D C:\Program Files (x86)\Screaming Frog SEO Spider
2018-04-17 09:33 - 2018-05-05 18:34 - 000020989 _____ C:\Users\sempe\.spyglass.properties
2018-04-17 09:31 - 2018-05-05 18:34 - 000000000 ____D C:\Users\sempe\.seospyglass
2018-04-17 09:30 - 2018-05-17 18:08 - 000081223 _____ C:\Users\sempe\.linkassistant.properties
2018-04-17 09:26 - 2018-05-17 18:08 - 000000000 ____D C:\Users\sempe\.linkassistant

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-05-17 20:10 - 2016-09-09 13:46 - 000000000 ____D C:\ProgramData\NVIDIA
2018-05-17 20:08 - 2016-06-25 07:23 - 000000000 ___RD C:\Users\sempe\Google Drive
2018-05-17 20:07 - 2016-06-25 00:36 - 000000000 __RDL C:\Users\sempe\OneDrive
2018-05-17 20:06 - 2018-03-31 09:22 - 000102112 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2018-05-17 20:06 - 2018-03-31 09:22 - 000044768 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2018-05-17 20:06 - 2018-03-22 13:54 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-05-17 20:06 - 2018-03-22 13:54 - 000112864 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2018-05-17 20:06 - 2016-06-25 00:33 - 000000000 __SHD C:\Users\sempe\IntelGraphicsProfiles
2018-05-17 20:05 - 2017-10-20 12:52 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-05-17 20:04 - 2017-09-29 16:45 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2018-05-17 20:00 - 2017-10-20 12:30 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-05-17 18:40 - 2018-04-16 15:58 - 000108925 _____ C:\Users\sempe\.websiteauditor.properties
2018-05-17 18:40 - 2018-04-16 15:36 - 000000000 ____D C:\Users\sempe\.websiteauditor
2018-05-17 18:40 - 2017-10-20 12:36 - 000000000 ____D C:\Users\sempe
2018-05-17 15:19 - 2016-06-25 07:12 - 000000000 ____D C:\Program Files (x86)\Overwatch
2018-05-17 15:18 - 2016-06-25 07:11 - 000000000 ____D C:\Users\sempe\AppData\Local\Battle.net
2018-05-17 15:17 - 2018-02-23 09:52 - 000002860 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3205350201-1289876752-4104875119-1001
2018-05-17 15:17 - 2018-02-02 08:49 - 000002762 _____ C:\WINDOWS\System32\Tasks\AdobeGCInvoker-1.0-MicrosoftAccount-semperaye@outlook.com
2018-05-17 15:17 - 2017-12-17 16:21 - 000002860 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3205350201-1289876752-4104875119-1002
2018-05-17 15:17 - 2017-11-14 11:45 - 000002988 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-05-17 15:17 - 2017-10-20 12:52 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2018-05-17 15:17 - 2017-10-20 12:52 - 000003344 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-05-17 15:17 - 2017-10-20 12:52 - 000003120 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-05-17 15:17 - 2017-10-20 12:52 - 000002220 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-05-17 15:17 - 2017-10-20 12:52 - 000000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2018-05-17 14:45 - 2016-06-25 07:09 - 000000000 ____D C:\Program Files (x86)\Battle.net
2018-05-17 08:50 - 2017-09-29 21:44 - 000000000 ____D C:\WINDOWS\INF
2018-05-17 07:45 - 2017-10-20 12:52 - 000004264 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2018-05-16 17:41 - 2017-07-27 20:32 - 000000000 ____D C:\Users\sempe\AppData\Roaming\vlc
2018-05-16 07:16 - 2016-06-25 23:02 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-05-16 07:10 - 2017-09-29 21:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-05-16 07:10 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-05-16 07:06 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-05-15 15:23 - 2016-06-26 09:33 - 000000000 ____D C:\ProgramData\Rosetta Stone
2018-05-15 15:07 - 2016-06-25 09:43 - 000000000 ____D C:\Users\sempe\Downloads\Rosetta.Stone.v3.4.7
2018-05-15 11:20 - 2017-04-10 12:55 - 000000000 ____D C:\Users\sempe\AppData\Roaming\tixati
2018-05-14 17:49 - 2016-07-16 01:51 - 000000132 _____ C:\Users\sempe\AppData\Roaming\Adobe PNG Format CC Prefs
2018-05-14 17:35 - 2016-06-25 22:35 - 000000000 ____D C:\Users\sempe\AppData\Local\Adobe
2018-05-13 22:11 - 2017-10-21 13:08 - 000000000 ____D C:\Users\sempe\AppData\Local\PlaceholderTileLogoFolder
2018-05-13 22:11 - 2017-10-20 12:37 - 000000000 ____D C:\Users\sempe\AppData\Local\Packages
2018-05-13 05:45 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\rescache
2018-05-12 19:23 - 2018-04-16 15:33 - 000018084 _____ C:\Users\sempe\.ranktracker.properties
2018-05-12 19:23 - 2018-04-16 14:44 - 000000000 ____D C:\Users\sempe\.ranktracker
2018-05-12 10:46 - 2017-07-05 10:04 - 000000000 ____D C:\Users\sempe\Downloads\Word Press Plugins
2018-05-11 13:51 - 2017-11-10 10:37 - 000196640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2018-05-11 13:51 - 2017-10-20 12:07 - 001027720 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2018-05-11 13:51 - 2017-10-20 12:07 - 000460520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2018-05-11 13:51 - 2017-10-20 12:07 - 000381552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2018-05-11 13:51 - 2017-10-20 12:07 - 000205976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2018-05-11 13:51 - 2017-10-20 12:07 - 000159120 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2018-05-11 13:51 - 2017-10-20 12:07 - 000111360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2018-05-11 13:51 - 2017-10-20 12:07 - 000085968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2018-05-11 13:51 - 2017-10-20 12:07 - 000046968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2018-05-10 16:38 - 2016-06-25 05:38 - 000000000 ____D C:\Users\sempe\AppData\Local\CrashDumps
2018-05-10 08:42 - 2017-10-20 12:49 - 001555852 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-05-10 08:38 - 2017-10-20 12:58 - 000000000 ___RD C:\Users\sempe\3D Objects
2018-05-10 08:38 - 2016-06-08 05:51 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-05-10 08:35 - 2017-10-20 12:30 - 000401632 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-05-09 20:02 - 2017-09-29 21:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2018-05-09 20:02 - 2017-09-29 21:46 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2018-05-09 20:02 - 2017-09-29 21:46 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-05-09 20:02 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-05-09 20:02 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-05-09 20:02 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-05-09 20:02 - 2017-09-29 16:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-05-09 20:02 - 2017-09-29 16:45 - 000000000 ____D C:\WINDOWS\servicing
2018-05-09 19:23 - 2017-06-02 18:54 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2018-05-09 19:23 - 2015-10-30 15:24 - 000000167 _____ C:\WINDOWS\win.ini
2018-05-09 19:07 - 2016-06-25 00:57 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-05-09 18:59 - 2017-10-11 10:23 - 141696960 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-05-09 18:59 - 2016-06-25 00:57 - 141696960 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-05-09 18:58 - 2017-09-29 21:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-05-05 18:14 - 2017-09-17 14:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2018-05-05 17:50 - 2017-06-02 18:51 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-05-05 17:50 - 2017-06-02 17:02 - 000000000 ____D C:\Program Files (x86)\MSECache
2018-05-05 17:36 - 2017-05-14 17:05 - 000000000 ____D C:\Users\sempe\AppData\Local\ElevatedDiagnostics
2018-05-05 09:43 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-05-04 07:37 - 2017-04-30 07:42 - 000000000 ____D C:\Users\sempe\AppData\Roaming\FileZilla
2018-04-30 14:28 - 2018-04-16 11:10 - 000001472 _____ C:\Users\sempe\Desktop\SEO PowerSuite Workflow.lnk
2018-04-30 14:28 - 2018-04-12 12:13 - 000001336 _____ C:\Users\sempe\Desktop\Scraping - Shortcut.lnk
2018-04-30 14:28 - 2018-04-12 10:45 - 000002698 _____ C:\Users\sempe\Desktop\Instagram Scraping Template - Shortcut.lnk
2018-04-30 14:28 - 2018-04-07 19:13 - 000002555 _____ C:\Users\sempe\Desktop\Twitter Scraping Template - Shortcut.lnk
2018-04-30 14:28 - 2018-04-06 13:09 - 000001281 _____ C:\Users\sempe\Desktop\LTO - Shortcut.lnk
2018-04-30 14:28 - 2018-03-30 16:31 - 000002263 _____ C:\Users\sempe\Desktop\Keyword Research Template - Shortcut.lnk
2018-04-30 14:28 - 2018-03-26 14:45 - 000002455 _____ C:\Users\sempe\Desktop\FB Scraping Template - Shortcut.lnk
2018-04-30 14:28 - 2018-03-24 09:25 - 000002835 _____ C:\Users\sempe\Desktop\Competitor Research Template - Shortcut.lnk
2018-04-30 14:28 - 2018-02-15 10:16 - 000001316 _____ C:\Users\sempe\Desktop\Fiverr - Shortcut.lnk
2018-04-30 14:28 - 2018-02-01 09:00 - 000001566 _____ C:\Users\sempe\Desktop\Convict Conditioning - Shortcut.lnk
2018-04-30 14:28 - 2018-01-28 10:06 - 000001828 _____ C:\Users\sempe\Desktop\how not to die meal plan 1-28-18 - Shortcut.lnk
2018-04-30 14:28 - 2017-12-03 14:01 - 000001354 _____ C:\Users\sempe\Desktop\Jodee CRBA - Shortcut.lnk
2018-04-30 14:28 - 2017-11-30 16:45 - 000001462 _____ C:\Users\sempe\Desktop\Transcripts Evaluation - Shortcut.lnk
2018-04-30 14:28 - 2017-08-09 13:01 - 000001341 _____ C:\Users\sempe\Desktop\Test Site - Shortcut.lnk
2018-04-30 14:28 - 2017-04-29 15:44 - 000001712 _____ C:\Users\sempe\Desktop\T-shirts - Shortcut.lnk
2018-04-30 14:28 - 2016-09-11 17:43 - 000001183 _____ C:\Users\sempe\Desktop\Google Drive - Shortcut.lnk
2018-04-30 14:28 - 2016-09-09 18:41 - 000001570 _____ C:\Users\sempe\Desktop\ADDRESS'S & PHONE #'S - Shortcut.lnk
2018-04-30 07:02 - 2016-06-25 05:45 - 000000000 ____D C:\Program Files\CCleaner
2018-04-28 10:28 - 2016-09-09 13:46 - 000000000 ____D C:\ProgramData\Package Cache
2018-04-28 08:43 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-04-27 13:58 - 2018-02-23 09:52 - 000002369 _____ C:\Users\sempe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-04-27 07:01 - 2017-09-29 16:05 - 000002263 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-04-26 13:58 - 2016-06-25 00:33 - 000000000 ____D C:\Users\sempe\AppData\Local\NVIDIA Corporation
2018-04-19 18:05 - 2017-05-14 10:01 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-04-19 18:04 - 2017-05-14 10:01 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-04-19 18:04 - 2016-06-08 05:48 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-04-19 17:21 - 2016-06-25 06:08 - 000000000 ____D C:\Program Files (x86)\Steam
2018-04-19 17:08 - 2016-06-25 00:33 - 000000000 ____D C:\Users\sempe\AppData\Local\NVIDIA
2018-04-19 17:04 - 2017-05-14 10:01 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-04-19 17:04 - 2016-09-11 18:14 - 000000000 ____D C:\temp
2018-04-19 16:52 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\Help
2018-04-19 16:22 - 2017-10-20 12:52 - 000004170 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7C2237F8-B46A-4B62-B14B-F6255D65512B}
2018-04-17 20:01 - 2018-04-15 17:05 - 000000000 ____D C:\Users\sempe\Desktop\Backlink Test

==================== Files in the root of some directories =======

2016-07-16 01:51 - 2018-05-14 17:49 - 000000132 _____ () C:\Users\sempe\AppData\Roaming\Adobe PNG Format CC Prefs
2017-06-04 13:30 - 2017-06-04 13:30 - 000034909 _____ () C:\Users\sempe\AppData\Roaming\Comma Separated Values.ADR
2018-04-01 14:27 - 2018-04-02 13:13 - 000000600 _____ () C:\Users\sempe\AppData\Local\PUTTY.RND

Some files in TEMP:
====================
2018-05-17 15:25 - 2018-05-17 15:25 - 000065536 ____N () C:\Users\sempe\AppData\Local\Temp\ICE_JNIRegistry5918276028207772094.dll
2018-05-17 09:29 - 2018-05-17 09:29 - 000065536 ____N () C:\Users\sempe\AppData\Local\Temp\ICE_JNIRegistry7580819377945616627.dll
2018-05-17 18:05 - 2018-05-17 18:05 - 000065536 ____N () C:\Users\sempe\AppData\Local\Temp\ICE_JNIRegistry7978929804075001691.dll
2018-05-17 14:38 - 2018-05-17 14:38 - 000065536 ____N () C:\Users\sempe\AppData\Local\Temp\ICE_JNIRegistry7983860638484243523.dll
2018-05-16 20:14 - 2018-05-16 20:14 - 000065536 ____N () C:\Users\sempe\AppData\Local\Temp\ICE_JNIRegistry8494219360714514250.dll
2018-05-17 18:18 - 2018-05-17 18:18 - 000065536 ____N () C:\Users\sempe\AppData\Local\Temp\ICE_JNIRegistry910357169493195612.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-16 19:42

==================== End of FRST.txt ============================

wmbscan.txt

Addition_17-05-2018 20.16.40.txt

Link to post
Share on other sites

Thanks for those logs, lets make clean install of Chrome:

If your Chrome Bookmarks are important do this first:

Go to this link: http://www.wikihow.com/Export-Bookmarks-from-Chrome follow the instructions and Export your Bookmarks from Chrome, save to your Desktop or similar. Note the instructions can also be used to Import the bookmarks.....

Continue for a clean install:

Download Chrome installer and save to install later: https://www.google.com/intl/en_uk/chrome/browser/desktop/index.html https://www.google.com/intl/en_usa/chrome/browser/desktop/index.html

Next,

Open Chrome and sign into your account, open a new tab and type or copy paste chrome://settings/syncSetup hit enter...

In the new window that opens "Sync everthing" will probably be selected, scroll down to and select "Managed sync data on Google Dashboard"

A new window will open, scroll down to and select "Reset Sync" that will clear synced data from Google Server...

Continue to next step to completely Uninstall Chrome....

Next.

Uninstall Chrome: https://support.google.com/chrome/answer/95319?hl=en-GB follow those instructions, ensure the option to "Also delete your browsing data" is selected. <<--- Very important!!

Navigate to C:\Users\Your user name\Appdata\Local from that folder delete the folder named Google (you will need to show hidden files/folders to see the folder Appdata)

For XP that will be My Computer > C:\ Documents and Settings\Your User Name\Application Data\Roaming

How to show hidden files and folders for windows: http://www.howtogeek.com/howto/windows-vista/show-hidden-files-and-folders-in-windows-vista/

Next,

Install Google Chrome

Next,

Import your Bookmarks... (instructions in the first step)

Next,

Install uBlock Origin for Chrome: https://chrome.google.com/webstore/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm?hl=en

Does that help...?
Link to post
Share on other sites

# -------------------------------
# Malwarebytes AdwCleaner 7.1.1.0
# -------------------------------
# Build:    04-27-2018
# Database: 2018-05-14.1
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    05-18-2018
# Duration: 00:00:12
# OS:       Windows 10 Home
# Scanned:  40858
# Detected: 2


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

PUP.Optional.Legacy             Ask
PUP.Optional.Legacy             AOL

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S03].txt ##########
 

Link to post
Share on other sites

I`ve never come across this issue before, run the following:

Please download Zemana AntiMalware and save it to your Desktop.
 
  • Install the program and once the installation is complete it will start automatically.
  • Without changing any options, press Scan to begin.
  • After the short scan is finished, if threats are detected press Next to remove them.
    Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please re-boot your computer manually.
     
  • Open Zemana AntiMalware again.
  • Click on user posted image icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • Attach saved report in your next message.


Next,

Download RogueKiller and save it on your desktop, ensure to download correct version..

RogueKiller (X86)

RogueKiller (x64)
 
  • Exit all running applications.
  • Double-click on RogueKiller.exe to launch the tool. On its first execution, RogueKiller will disply the software license (EULA), click on "Accept" to continue.
  • If RogueKiller is unable to load, do not hesitate to try launching it several times or rename it winlogon.
  • Click "Start Scan" to begin the analysis. This may take some time.
  • Once the scan is complete, click the "Open TXT" button to display the scan report.
  • Copy/Paste it's content in your next reply.


Do not use the Remove Selected option until i`ve had a look at the log..

Thanks,

Kevin..
Link to post
Share on other sites

Not much found.... 

 

RogueKiller V12.12.17.0 (x64) [May 14 2018] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.16299) 64 bits version
Started in : Normal mode
User : sempe [Administrator]
Started from : C:\Users\sempe\Downloads\RogueKiller_portable64.exe
Mode : Delete -- Date : 05/18/2018 18:30:51 (Duration : 01:38:54)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 4 ¤¤¤
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3205350201-1289876752-4104875119-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://dell15.msn.com/?pc=DCTE  -> Replaced (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3205350201-1289876752-4104875119-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://dell15.msn.com/?pc=DCTE  -> Replaced (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3205350201-1289876752-4104875119-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://dell15.msn.com/?pc=DCTE  -> Replaced (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3205350201-1289876752-4104875119-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://dell15.msn.com/?pc=DCTE  -> Replaced (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome)

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 [Too big!] ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 5 ¤¤¤
[PUM.HomePage][Firefox:Config] q57wk9ww.default : user_pref("browser.startup.homepage", "https://news.google.com/"); -> Not selected
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [https://news.google.com/] -> Not selected
[PUM.HomePage][Chrome:Config] Profile 3 [SecurePrefs] : homepage [http://www.fiverr.com/] -> Not selected
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [http://news.google.com/] -> Not selected
[PUM.HomePage][Chrome:Config] Profile 3 [SecurePrefs] : session.startup_urls [https://www.fiverr.com/] -> Not selected

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ02ABD100H +++++
--- User ---
[MBR] f9376a1dd800caf0a337d4a9243e2fd2
[BSP] fc7e198aa605bde5e46652156ac849c8 : Empty|VT.Unknown MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 500 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1026048 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 1288192 | Size: 941162 MB
3 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1928787968 | Size: 450 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 1929709568 | Size: 11628 MB
User = LL1 ... OK
User = LL2 ... OK

zemana-2018.05.18-16.59.38-i0-t92-d2.txt

Link to post
Share on other sites

This very odd for sure, Tampermonkey is an extension that can be added to most usual browsers such as Chrome, Firefox, Opera etc etc... In your case it would seem that only Chrome is affected. This extension is not malicious and is not installed via 3rd party software as far as i`m aware.

Tampermonkey does have a website base and forum, maybe is worthwhile asking at the forum for advice. As TM extension returns when Chrome is opened it is possible that Chrome sync can put it back. Did you definitely reset sync to remove all synced data from Googles servers...?

https://tampermonkey.net/faq.php?ext=dhdg#Q301

Link to post
Share on other sites

3 hours ago, kevinf80 said:

This very odd for sure, Tampermonkey is an extension that can be added to most usual browsers such as Chrome, Firefox, Opera etc etc... In your case it would seem that only Chrome is affected. This extension is not malicious and is not installed via 3rd party software as far as i`m aware.

Tampermonkey does have a website base and forum, maybe is worthwhile asking at the forum for advice. As TM extension returns when Chrome is opened it is possible that Chrome sync can put it back. Did you definitely reset sync to remove all synced data from Googles servers...?

https://tampermonkey.net/faq.php?ext=dhdg#Q301

Hi. Yes I did certainly restet sync and removed all data. Later I tried to connect to another laptop and sync up, I had no problems on the other laptop. This showed me that both it was not sync, and it was a local problem. There is something on my PC that is installing Tampermonkey and adding those two pup's that seem to add to ask and aol to available search options in chome. Since this happens without opening any programs, it must be something that is running in the background. I did varoius boot scan for start up programs and such and never found anything.

As long as you can tell me that those pup's are not really that dangerous, as they only seem to add search providers, then I'm going to just give up on this. I'll just run the adware cleaner after all my chrome accounts have been added.

Thanks.

Link to post
Share on other sites

Due to the lack of feedback, this topic is closed to prevent others from posting here.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this topic. Other members who need assistance please start your own topic in a new thread.

Thanks

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.