Schritt 2 und 3 erledigt, alle tencent Programme (qq, tm) sind gelöscht, das ist großer Mist. Muß jetzt alles neu installieren.
das Log bisher: Code:
# AdwCleaner v6.047 - Bericht erstellt am 20/06/2017 um 20:47:28
# Aktualisiert am 19/05/2017 von Malwarebytes
# Datenbank : 2017-06-20.1 [Lokal]
# Betriebssystem : Windows 10 Enterprise (X64)
# Benutzername : moxito - MSI
# Gestartet von : C:\Users\moxito\Downloads\AdwCleaner_6.047.exe
# Modus: Löschen
# Unterstützung : https://www.malwarebytes.com/support
***** [ Dienste ] *****
[-] Dienst gelöscht: tsnethlpx64
[-] Dienst gelöscht: QPCore
[-] Dienst gelöscht: QQMusicService
[-] Dienst gelöscht: TenCommProtect
[-] Dienst gelöscht: MSLN
[-] Dienst gelöscht: sogouupdate
***** [ Ordner ] *****
[-] Ordner gelöscht: C:\ProgramData\58bca3a8
[-] Ordner gelöscht: C:\Users\moxito\AppData\Local\Tencent
[-] Ordner gelöscht: C:\Users\moxito\AppData\LocalLow\Tencent
[-] Ordner gelöscht: C:\Users\moxito\AppData\Roaming\Tencent
[-] Ordner gelöscht: C:\Users\moxito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
[-] Ordner gelöscht: C:\Users\moxito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QVOD
[-] Ordner gelöscht: C:\Program Files\Common Files\Tencent
[-] Ordner gelöscht: C:\Users\moxito\AppData\Local\VirtualStore\Program Files (x86)\QVOD
[-] Ordner gelöscht: C:\Users\moxito\AppData\Local\VirtualStore\Program Files (x86)\Tencent
[-] Ordner gelöscht: C:\QvodPlayer
[-] Ordner gelöscht: C:\Tencent
[-] Ordner gelöscht: C:\ProgramData\TXQMPC
[-] Ordner gelöscht: C:\ProgramData\Tencent
[#] Ordner mit Neustart gelöscht: C:\ProgramData\Application Data\TXQMPC
[#] Ordner mit Neustart gelöscht: C:\ProgramData\Application Data\Tencent
[-] Ordner gelöscht: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
[-] Ordner gelöscht: C:\Users\Public\Documents\Tencent
[-] Ordner gelöscht: C:\Program Files (x86)\Tencent
[-] Ordner gelöscht: C:\Program Files (x86)\Common Files\Tencent
[-] Ordner gelöscht: C:\Program Files (x86)\Common Files\freemake shared
[-] Ordner gelöscht: C:\Users\moxito\AppData\Local\Temp\Tencent
[-] Ordner gelöscht: C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Tencent
[-] Ordner gelöscht: C:\WINDOWS\SysWOW64\sstmp
***** [ Dateien ] *****
[-] Datei gelöscht: C:\WINDOWS\SysNative\log\iSafeKrnlCall.log
[#] Datei gelöscht: C:\WINDOWS\SysNative\drivers\TenCommProtect64.sys
[-] Datei gelöscht: C:\END
[-] Datei gelöscht: C:\WINDOWS\rsrcs.dll
[-] Datei gelöscht: C:\Users\Public\Documents\cfg.ini
[-] Datei gelöscht: C:\Users\Public\Documents\cc.ini
[-] Datei gelöscht: C:\Users\Public\Documents\temp.dat
[-] Datei gelöscht: C:\Users\Public\Documents\report.dat
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Verknüpfungen ] *****
***** [ Aufgabenplanung ] *****
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel gelöscht: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SCService
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\SCService
[#] Schlüssel mit Neustart gelöscht: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\scservice
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\scservice
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\Classes\Tencent
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\Classes\Tencent
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Baiduyunguanjia
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\BaiduYunGuanjia.torrent
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\metnsd
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\PCSU.SysUtils
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Tencent
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Classes\Tencent
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Baiduyunguanjia
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\BaiduYunGuanjia.torrent
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\metnsd
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\PCSU.SysUtils
[#] Schlüssel mit Neustart gelöscht: [x64] HKLM\SOFTWARE\Classes\Tencent
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\AppID\{6517DD27-EA6F-4947-9DEA-F9C487BB1020}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\AppID\{1E9BD312-7C8C-4422-906D-897F6D7714F2}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{8FC1EE75-72B3-4A23-B987-2B1C4C8A611B}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\CLSID\{B9E49847-9822-4139-BC55-7173ED1ADA11}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{B9E49847-9822-4139-BC55-7173ED1ADA11}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{6C42038D-817A-472C-8C2A-EF46F1DA576D}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{873C7DA8-195D-4D5A-B830-C5E2831901EA}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{2E0D1C92-9589-4755-BB55-7117F2155736}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\Interface\{495151D2-561C-419E-A7DC-741108602464}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\TypeLib\{6517DD27-EA6F-4947-9DEA-F9C487BB1020}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\TypeLib\{6CB9D494-2482-4277-9E45-22F36C471461}
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\TypeLib\{3157E247-2784-4028-BF0F-52D6DDC70E1B}
[-] Schlüssel gelöscht: HKU\.DEFAULT\Software\UpgSvr
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\Burn4Free
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\Installer
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\System Healer
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\QvodPlayer
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\AutoTime
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\SNDA
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\dlr
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\PopWnd
[-] Schlüssel gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\UpgSvr
[#] Schlüssel mit Neustart gelöscht: HKU\S-1-5-18\Software\UpgSvr
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\Burn4Free
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\Installer
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\System Healer
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\QvodPlayer
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\AutoTime
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\SNDA
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\dlr
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\PopWnd
[#] Schlüssel mit Neustart gelöscht: HKCU\Software\UpgSvr
[-] Schlüssel gelöscht: HKLM\SOFTWARE\QvodPlayer
[-] Schlüssel gelöscht: HKLM\SOFTWARE\InterHop
[-] Schlüssel gelöscht: HKLM\SOFTWARE\amule-custom
[-] Schlüssel gelöscht: HKLM\SOFTWARE\mylucky123Software
[-] Schlüssel gelöscht: HKLM\SOFTWARE\HPReyos
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QvodPlayer
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Burn4Free
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\Installer
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\System Healer
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\QvodPlayer
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\AutoTime
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\SNDA
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\dlr
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\PopWnd
[#] Schlüssel mit Neustart gelöscht: [x64] HKCU\Software\UpgSvr
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\{1f7ee1a8-4436-4ffc-b97b-b5b01e87d3d2}
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C767D9D7BB3F9C4B839FF09B6C80DCF
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EE2F0310EBEC29A0C48C035C43786AA
[-] Schlüssel gelöscht: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2A47D6F1D42DD81A292C027724D291
[-] Daten wiederhergestellt: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Wert gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\Microsoft\Windows\CurrentVersion\Run [QQ2009]
[-] Wert gelöscht: HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [QQ2009]
[#] Wert mit Neustart gelöscht: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [QQ2009]
[#] Wert mit Neustart gelöscht: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [QQ2009]
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
[-] Schlüssel gelöscht: HKLM\SOFTWARE\MozillaPlugins\@qq.com/TXSSO
[-] Schlüssel gelöscht: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
[-] Schlüssel gelöscht: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\com.qq.qmchext
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Classes\AppID\QMContextUninstall.DLL
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\QvodCDAudioOnArrival
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\QvodDVDMovieOnArrival
[-] Schlüssel gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\QvodMediaOnArrival
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents [qhtp]
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents [qvod]
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayCDAudioOnArrival [QvodCDAudioOnArrival]
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayDVDMovieOnArrival [QvodDVDMovieOnArrival]
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayMusicFilesOnArrival [QvodMediaOnArrival]
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayVideoFilesOnArrival [QvodMediaOnArrival]
[-] Schlüssel gelöscht: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
[-] Schlüssel gelöscht: HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
[#] Schlüssel mit Neustart gelöscht: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\e24b7131-d039-43cb-9e6f-ad4be601ec1f
[#] Schlüssel mit Neustart gelöscht: HKLM\SYSTEM\ControlSet001\Control\Power\User\PowerSchemes\04262113-2a31-48e1-b4bb-3b42174bea0f
[-] Schlüssel gelöscht: HKCU\Software\MozillaPlugins\@1.qq.com/npqqwebgame
[-] Schlüssel gelöscht: HKLM\SOFTWARE\MozillaPlugins\@qq.com/npQQGameAssist
[-] Schlüssel gelöscht: HKLM\SOFTWARE\MozillaPlugins\@qq.com/npqscall
[-] Schlüssel gelöscht: HKLM\SOFTWARE\MozillaPlugins\@qq.com/QQPhotoDrawEx
[-] Schlüssel gelöscht: HKLM\SOFTWARE\MozillaPlugins\@qq.com/QzoneMusic
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]
[-] Wert gelöscht: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [ArcherGroupEx]
[-] Schlüssel gelöscht: HKCU\SOFTWARE\Clients\StartMenuInternet\ChromeHTML
[-] Schlüssel gelöscht: HKLM\SYSTEM\CurrentControlSet\Control\iSafeKrnlBoot
***** [ Browser ] *****
*************************
:: "Tracing" Schlüssel gelöscht
:: Winsock Einstellungen zurückgesetzt
:: Proxy Einstellungen zurückgesetzt
:: Internet Explorer Richtlinien gelöscht
:: Chrome Richtlinien gelöscht
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [12581 Bytes] - [20/06/2017 20:47:28]
C:\AdwCleaner\AdwCleaner[S0].txt - [10718 Bytes] - [20/06/2017 20:42:28]
C:\AdwCleaner\AdwCleaner[S1].txt - [11848 Bytes] - [20/06/2017 20:45:17]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [12803 Bytes] ########## das Log von JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 10 Enterprise x64
Ran by moxito (Administrator) on 20.06.2017 at 21:00:01,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 6
Failed to delete: C:\Program Files (x86)\sogouinput (Folder)
Successfully deleted: C:\ProgramData\sogouinput (Folder)
Successfully deleted: C:\ProgramData\updater (Folder)
Successfully deleted: C:\Users\Public\thunder network (Folder)
Successfully deleted: C:\WINDOWS\system32\Tasks\SogouImeMgr (Task)
Successfully deleted: C:\Program Files (x86)\qqmailplugin (Folder)
Registry: 4
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C7334B-5657-41e1-8F79-F6AACECA05F4} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDD362CF-523B-4BC9-8FDC-58F93B6BC945} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9C7334B-5657-41e1-8F79-F6AACECA05F4} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DDD362CF-523B-4BC9-8FDC-58F93B6BC945} (Registry Key)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.06.2017 at 21:00:51,85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ mbam: Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 20.06.17
Scan-Zeit: 21:06
Protokolldatei:
Administrator: Ja
-Softwaredaten-
Version: 3.1.2.1733
Komponentenversion: 1.0.141
Version des Aktualisierungspakets: 1.0.2194
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: MSI\moxito
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 397536
Erkannte Bedrohungen: 5
In die Quarantäne verschobene Bedrohungen: 5
Abgelaufene Zeit: 1 Min., 49 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 2
PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE, In Quarantäne, [9416], [408200],1.0.2194
PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\CONSOLE\TASKENG.EXE, In Quarantäne, [9416], [408199],1.0.2194
Registrierungswert: 3
PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE|WINDOWPOSITION, In Quarantäne, [9416], [408200],1.0.2194
PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_WINDOWSPOWERSHELL_V1.0_POWERSHELL.EXE|WINDOWPOSITION, In Quarantäne, [9416], [408201],1.0.2194
PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\CONSOLE\TASKENG.EXE|WINDOWPOSITION, In Quarantäne, [9416], [408199],1.0.2194
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 0
(keine bösartigen Elemente erkannt)
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end) FRST Nochmal:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-06-2017 01
Ran by moxito (administrator) on MSI (20-06-2017 21:29:05)
Running from C:\Users\moxito\Desktop
Loaded Profiles: moxito (Available Profiles: moxito)
Platform: Windows 10 Enterprise Version 1607 (X64) Language: Englisch (Vereinigte Staaten)
Internet Explorer Version 11 (Default browser: "C:\Users\moxito\AppData\Local\360Browser\Browser\Application\360browser.exe" -- "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Baidu, Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BHipsSvc.exe
(Baidu, Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BavSvc.exe
(Ellora Assets Corp.) C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
(Hauppauge Computer Works) C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Dragon Center\MSI_ActiveX_Service.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Nitro PDF Software) C:\Program Files\Nitro\Reader 5\NitroPDFReaderDriverService5x64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Wondershare) C:\Program Files (x86)\Wondershare\WAF\2.3.1.204\WsAppService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Baidu, Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\bavhm.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
() C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) Corporation) C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\Dragon Center\Dragon Center.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(Microsoft Corporation) C:\Windows\System32\CastSrv.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\MSI\Dragon Gaming Center\Dragon Gaming Center.exe
() C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2UILauncher.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
() C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2Svc32.exe
() C:\Program Files\Nahimic\Nahimic2\UserInterface\x64\Nahimic2Svc64.exe
(SlySoft, Inc.) C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe
(QuestSoft) C:\Program Files (x86)\QTranslate\QTranslate.exe
() C:\Program Files (x86)\SlySoft\AnyDVD\ADvdDiscHlp64.exe
(网易公司) C:\Users\moxito\AppData\Local\Youdao\Dict\Application\YodaoDict.exe
(网易公司) C:\Users\moxito\AppData\Local\Youdao\Dict\Application\6.3.69.8341\YoudaoIE.exe
() C:\Users\moxito\AppData\Local\Youdao\Dict\Application\6.3.69.8341\YoudaoDictHelper.exe
(Ritlabs S.R.L.) C:\Program Files (x86)\The Bat!\thebat.exe
() C:\Users\moxito\AppData\Roaming\baidu\BaiduYunGuanjia\yundetectservice.exe
(YY Inc.) C:\Program Files (x86)\YY\YY.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe
(Baidu, Inc.) C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BavTray.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(SteelSeries ApS) C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMon.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(网易公司) C:\Users\moxito\AppData\Local\Youdao\Dict\Application\6.3.69.8341\WordBook.exe
() C:\Users\moxito\AppData\Local\Youdao\Dict\Application\6.3.69.8341\YoudaoWSH.exe
() C:\Users\moxito\AppData\Roaming\duowan\yy\yycomstore\2052\com.yy.webrunlogin\65547\yyqlogin.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
() C:\Users\moxito\AppData\Local\Youdao\Dict\Application\6.3.69.8341\YoudaoDictHelper.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Tencent) C:\Program Files (x86)\Tencent\QQIntl\Bin\QQ.exe
(Tencent) C:\Program Files (x86)\Tencent\QQIntl\Bin\TXPlatform.exe
(Qihu 360 Software Co., Ltd.) C:\Users\moxito\AppData\Local\360Browser\Browser\Application\360browser.exe
(Qihu 360 Software Co., Ltd.) C:\Users\moxito\AppData\Local\360Browser\Browser\Application\360browser.exe
(Qihu 360 Software Co., Ltd.) C:\Users\moxito\AppData\Local\360Browser\Browser\Application\360browser.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9198080 2017-02-06] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [297984 2015-12-09] (MSI)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Nahimic2UILauncher] => C:\Program Files\Nahimic\Nahimic2\UserInterface\Nahimic2UILauncher.exe [705208 2017-01-13] ()
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [Baidu Antivirus] => C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BavTray.exe [1998832 2017-01-28] (Baidu, Inc.)
HKLM-x32\...\Run: [vmware-tray] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [103536 2011-08-22] (VMware, Inc.)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe [1971856 2016-11-18] ()
HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [ctfmon] => C:\WINDOWS\system32\ctfmon.exe [10752 2016-07-16] (Microsoft Corporation)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [AnyDVD] => C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe [9604008 2015-12-12] (SlySoft, Inc.)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [QTranslate] => C:\Program Files (x86)\QTranslate\QTranslate.exe [642048 2016-05-12] (QuestSoft)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [YYAssistant] => C:\Program Files (x86)\YY\8.24.0.2\\yyassistant.exe [335600 2017-06-12] (YY Inc.)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [YodaoDict] => C:\Users\moxito\AppData\Local\Youdao\Dict\Application\YodaoDict.exe [5552192 2016-11-25] (网易公司)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [thebat_startup] => C:\Program Files (x86)\The Bat!\thebat.exe [11954536 2007-10-31] (Ritlabs S.R.L.)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [255224 2016-11-29] (TomTom)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [TM] => "C:\Program Files (x86)\Tencent\TM2008\Bin\TM.exe" /background
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [BaiduYunGuanjia] => C:\Users\moxito\AppData\Roaming\baidu\BaiduYunGuanjia\baidunetdisk.exe [7757856 2017-06-16] ()
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [BaiduYunDetect] => C:\Users\moxito\AppData\Roaming\baidu\BaiduYunGuanjia\YunDetectService.exe [1052192 2017-06-16] ()
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [YfftPack] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\moxito\AppData\Local\Ambworks\wpnlefjp.dll <===== ATTENTION
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [YY] => C:\Program Files (x86)\YY\YY.exe [151792 2017-06-12] (YY Inc.)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Run: [QQ2009] => C:\Program Files (x86)\Tencent\QQIntl\Bin\QQ.exe [97976 2017-06-20] (Tencent)
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BavShx64.dll [2017-01-28] (Baidu, Inc.)
ShellIconOverlayIdentifiers: [KzShlobj] -> {AAA0C5B8-933F-4200-93AD-B143D7FFF9F2} => -> No File
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-12-09]
ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SteelSeries Engine 3.lnk [2017-06-16]
ShortcutTarget: SteelSeries Engine 3.lnk -> C:\Program Files\SteelSeries\SteelSeries Engine 3\SteelSeriesEngine3.exe (SteelSeries ApS)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk [2017-02-11]
ShortcutTarget: UltraMon.lnk -> C:\Windows\Installer\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}\IcoUltraMon.ico ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinTV Recording Status.lnk [2016-12-09]
ShortcutTarget: WinTV Recording Status.lnk -> C:\Program Files (x86)\WinTV\WinTV8\WinTVTray.exe (Hauppauge Computer Works, Inc.)
Startup: C:\Users\moxito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CCTalk.lnk [2016-12-09]
ShortcutTarget: CCTalk.lnk -> C:\Users\moxito\AppData\Roaming\Hujiang\Setup\PreInst\CCLaunch.exe (Hujiang)
Startup: C:\Users\moxito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar704.lnk [2017-06-20]
ShortcutTarget: Sidebar704.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{1f590c30-fd8d-44ea-ae52-5c965539d833}: [DhcpNameServer] 82.163.143.157
Tcpip\..\Interfaces\{38ff234b-697a-4a3c-99af-17abf95b27e9}: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{ddecc736-557e-44c0-b1c3-dbe0f06f526f}: [DhcpNameServer] 82.163.143.157
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131261445025659793&GUID=D8CC01CB-AEB0-4853-A5B1-0C8D1E99C72E
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2017-04-11] (Microsoft Corporation)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_112\bin\ssv.dll [2016-11-25] (Oracle Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_112\bin\jp2ssv.dll [2016-11-25] (Oracle Corporation)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\ProgramData\Wondershare\Video Converter Ultimate\WSBrowserAppMgr.dll [2016-11-18] (Wondershare)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
DPF: HKLM-x32 {1E525898-EE12-4002-9374-82D15147F762} hxxp://player.cntv.cn/flashplayer/config/plugins/wCNTVLive212.dll
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation)
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 - No File
FireFox:
========
FF ProfilePath: C:\Users\moxito\AppData\Roaming\TomTom\HOME\Profiles\crxg47tn.default [2017-04-04]
FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2017-02-08] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-12-09] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [WSVCU@Wondershare.com] - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi
FF Extension: (Wondershare Video Converter Ultimate) - C:\ProgramData\Wondershare\Video Converter Ultimate\WSVCU@Wondershare.com_xpi [2017-02-12]
FF HKU\S-1-5-21-1078665582-1449517287-1295239923-1001\...\Firefox\Extensions: [dict@www.youdao.com] - C:\Users\moxito\AppData\Local\Youdao\Dict\Application\stable\extensions\firefox => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-18] ()
FF Plugin: @java.com/DTPlugin,version=11.112.2 -> C:\Program Files\Java\jre1.8.0_112\bin\dtplugin\npDeployJava1.dll [2016-11-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.112.2 -> C:\Program Files\Java\jre1.8.0_112\bin\plugin2\npjp2.dll [2016-11-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-18] ()
FF Plugin-x32: @baidu.com/YunWebDetectPlugin -> C:\Users\moxito\AppData\Roaming\baidu\BaiduYunGuanjia\npYunWebDetect.dll [2017-06-16] (Baidu.com, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-11-15] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Reader 5\npnitromozilla.dll [2016-03-03] (Nitro PDF)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-18] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-18] (NVIDIA Corporation)
FF Plugin-x32: @qq.com/npchrome -> C:\Program Files (x86)\Common Files\Tencent\Npchrome\npchrome.dll [2017-06-20] (Tencent)
FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll [2017-06-20] (Tencent)
FF Plugin-x32: @qq.com/QQMiniDLPlugin -> C:\Program Files (x86)\Common Files\Tencent\QQMiniDL\60\Browser\npXFMiniDLPlugin.dll [No File]
FF Plugin-x32: @tencent.com/npQQMailWebKit,version=1.0.0.1 -> C:\Program Files (x86)\QQMailPlugin\npQQMailWebKit.dll [No File]
FF Plugin-x32: @tencent.com/nptxftnWebKit,version=1.0.0.1 -> C:\Program Files (x86)\QQMailPlugin\nptxftnWebKit.dll [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin HKU\S-1-5-21-1078665582-1449517287-1295239923-1001: duowan.com/Checker -> C:\Program Files (x86)\Common Files\duowan\yy\YYSSO\1.0.0.8\npChecker.dll [2016-11-21] (广州多玩信息技术有限公司)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-11-15] (Microsoft Corporation)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [315472 2015-06-29] (Windows (R) Win 7 DDK provider)
R2 BavSvc; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BavSvc.exe [2791312 2017-01-28] (Baidu, Inc.)
S3 BdSandboxSrv; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BdSandboxSrv64.exe [264688 2017-01-28] (Baidu, Inc.)
R2 BHipsSvc; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BHipsSvc.exe [531232 2017-01-28] (Baidu, Inc.)
S3 BstHdAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Service.exe [486936 2016-11-23] (BlueStack Systems, Inc.)
S3 BstHdLogRotatorSvc; C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe [470552 2016-11-23] (BlueStack Systems, Inc.)
S3 BstHdPlusAndroidSvc; C:\Program Files (x86)\Bluestacks\HD-Plus-Service.exe [511512 2016-11-23] (BlueStack Systems, Inc.)
S3 ehRecvr; C:\WINDOWS\ehome\ehRecvr.exe [713728 2015-09-02] (Microsoft Corporation) [File not signed]
S3 ehSched; C:\WINDOWS\ehome\ehsched.exe [177152 2015-09-02] (Microsoft Corporation) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2016-08-21] (Macrovision Europe Ltd.) [File not signed]
R2 FreemakeVideoCapture; C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe [9216 2017-01-24] (Ellora Assets Corp.) [File not signed]
R2 HauppaugeTVServer; C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe [586536 2016-10-10] (Hauppauge Computer Works)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation)
R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [451072 2015-10-06] (Rivet Networks) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MCRL; C:\ProgramData\Microsoft\VisualStudio\14.0\2052\msmg.dll [368128 2016-12-09] () [File not signed]
S3 Mcx2Svc; C:\WINDOWS\system32\Mcx2Svc.dll [83968 2015-09-05] (Microsoft Corporation) [File not signed]
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2015-12-09] (Micro-Star International Co., Ltd.) [File not signed]
R2 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\Dragon Center\MSI_ActiveX_Service.exe [62392 2017-04-24] (Micro-Star INT'L CO., LTD.)
R2 NitroReaderDriverReadSpool5; C:\Program Files\Nitro\Reader 5\NitroPDFReaderDriverService5x64.exe [327328 2016-03-03] (Nitro PDF Software)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [382248 2007-08-03] (Nero AG)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-18] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [449984 2017-05-18] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246888 2016-06-07] (Synaptics Incorporated)
R2 VMAuthdService; C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe [79872 2011-08-22] (VMware, Inc.) [File not signed]
R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [11837440 2011-08-22] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)
R2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.1.204\WsAppService.exe [437392 2016-11-16] (Wondershare)
R2 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [18232 2016-11-09] (Intel(R) Corporation)
S3 QTService; C:\Program Files (x86)\Tencent\QTalk\QTService.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [150440 2015-12-02] (SlySoft, Inc.)
R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [150440 2015-12-02] (SlySoft, Inc.)
R3 BdApiUtil; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BdApiUtil64.sys [116968 2017-01-28] (Baidu, Inc.)
S3 bdark64; C:\Windows\system32\drivers\bdark64.sys [78792 2015-05-28] ()
R3 BdCameraProtect; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\BdCameraProtect64.sys [25032 2017-01-28] (Baidu, Inc.)
S3 BdSandbox; C:\Windows\System32\drivers\BdSandbox.sys [236920 2015-03-05] (Baidu, Inc.)
R1 Bfilter; C:\Windows\System32\drivers\Bfilter.sys [61896 2016-08-21] (Baidu, Inc.)
R1 BfLwf; C:\WINDOWS\system32\DRIVERS\bwcW10x64.sys [141896 2015-09-30] (Rivet Networks, LLC.)
R1 Bfmon; C:\Windows\System32\drivers\Bfmon.sys [38344 2016-08-21] (Baidu, Inc.)
S0 Bhbase; C:\WINDOWS\System32\drivers\Bhbase.sys [83144 2017-01-28] (Baidu, Inc.)
R1 Bnbase; C:\WINDOWS\System32\drivers\bnbasex64.sys [62792 2016-08-21] (Baidu, Inc.)
R1 Bndef; C:\Windows\System32\drivers\bndef64.sys [485672 2016-08-21] (Baidu, Inc.)
R3 Bnmon; C:\Program Files (x86)\Baidu Security\Baidu Antivirus\5.4.3.148966.1\Bnmon64.sys [82376 2017-01-28] (Baidu, Inc.)
R1 Bprotect; C:\Windows\System32\drivers\Bprotect.sys [262088 2016-08-21] (Baidu, Inc.)
S3 BstHdDrv; C:\Program Files (x86)\Bluestacks\HD-Hypervisor-amd64.sys [152672 2016-11-23] (BlueStack Systems)
S3 BstkDrv; C:\Program Files (x86)\Bluestacks\BstkDrv.sys [270904 2016-11-08] (Bluestack System Inc. )
S3 BTHPORT; C:\WINDOWS\System32\drivers\BTHport.sys [967168 2016-11-11] (Microsoft Corporation) [File not signed]
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-27] (Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-05-25] ()
R3 flex1500; C:\WINDOWS\system32\drivers\flex1500.sys [265312 2012-11-29] (Jungo)
R3 flex1500; C:\Windows\SysWOW64\drivers\flex1500.sys [265312 2012-11-29] (Jungo)
R2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [37064 2016-08-24] (Intel Corporation)
R3 KillerEth; C:\WINDOWS\System32\drivers\e2xw10x64.sys [162456 2016-08-21] (Qualcomm Atheros, Inc.)
S3 libusbK; C:\WINDOWS\System32\drivers\libusbK.sys [47200 2016-12-27] (hxxp://libusb-win32.sourceforge.net)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188312 2017-06-20] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [113592 2017-06-20] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [44960 2017-06-20] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [252832 2017-06-20] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-06-20] (Malwarebytes)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvmii.inf_amd64_69ca8597af61d80b\nvlddmkm.sys [14458264 2017-05-19] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-05-03] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48248 2017-05-03] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-05-18] (NVIDIA Corporation)
R3 Qcamain10x64; C:\WINDOWS\System32\drivers\Qcamain10x64.sys [2336768 2016-07-16] (Qualcomm Atheros, Inc.)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [752856 2015-05-29] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42600 2016-06-07] (Synaptics Incorporated)
R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [46440 2017-04-06] (SteelSeries ApS)
R3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [45896 2017-05-12] (SteelSeries ApS)
R3 ssps2; C:\WINDOWS\System32\drivers\ssps2.sys [38720 2016-11-03] (SteelSeries ApS)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-27] (Samsung Electronics Co., Ltd.)
S3 SundtekMTV; C:\WINDOWS\system32\DRIVERS\sundtekmtv64.sys [365776 2015-12-10] (Sundtek Electronics)
R3 TT4650_SRV_64; C:\WINDOWS\system32\drivers\ttConnect4650_64.sys [436736 2015-11-24] (CityCom GmbH)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
R1 VBoxNetAdp; C:\WINDOWS\System32\drivers\VBoxNetAdp6.sys [132120 2016-11-21] (Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [206416 2016-11-21] (Oracle Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WINIO; C:\Program Files (x86)\MSI\Dragon Center\winio64.sys [15160 2015-06-11] ()
S1 eougywyt; \??\C:\WINDOWS\system32\drivers\eougywyt.sys [X]
S3 GSVxDrv; \??\C:\Program Files\YYBox\drivers\GSVxDrv\GSVxDrv.sys [X]
U2 QQMicroGameBoxService; no ImagePath
S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-20 21:28 - 2017-06-20 21:28 - 00000000 ____D C:\Users\moxito\Desktop\FRST-OlderVersion
2017-06-20 21:25 - 2017-06-20 21:25 - 00000000 ____D C:\Users\Public\Documents\Tencent
2017-06-20 21:25 - 2017-06-20 21:25 - 00000000 ____D C:\Users\moxito\AppData\Local\Google
2017-06-20 21:25 - 2017-06-20 21:25 - 00000000 ____D C:\Program Files (x86)\Tencent
2017-06-20 21:22 - 2017-06-20 21:27 - 00000000 ____D C:\Users\moxito\AppData\Roaming\Tencent
2017-06-20 21:04 - 2017-06-20 21:11 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-06-20 21:04 - 2017-06-20 21:11 - 00113592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-06-20 21:04 - 2017-06-20 21:11 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-06-20 21:04 - 2017-06-20 21:11 - 00044960 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-06-20 21:04 - 2017-06-20 21:04 - 00188312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-06-20 21:04 - 2017-06-20 21:04 - 00001872 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-06-20 21:04 - 2017-06-20 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-06-20 21:04 - 2017-06-20 21:04 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-20 21:04 - 2017-06-20 21:04 - 00000000 ____D C:\Program Files\Malwarebytes
2017-06-20 21:04 - 2017-05-25 11:58 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-06-20 21:03 - 2017-06-20 21:04 - 64232976 _____ (Malwarebytes ) C:\Users\moxito\Downloads\mb3-setup-consumer-3.1.2.1733-1.0.141-1.0.2092.exe
2017-06-20 21:00 - 2017-06-20 21:00 - 00001582 _____ C:\Users\moxito\Desktop\JRT.txt
2017-06-20 20:58 - 2017-06-20 20:58 - 01663672 _____ (Malwarebytes) C:\Users\moxito\Downloads\JRT.exe
2017-06-20 20:54 - 2017-06-20 20:56 - 00000000 ____D C:\Users\moxito\AppData\Local\F524E5C1-49AC-4835-B859-6FDC260E6394
2017-06-20 20:53 - 2017-06-20 21:11 - 00000486 _____ C:\WINDOWS\Tasks\HuanjuGameUpdate.job
2017-06-20 20:53 - 2017-06-20 20:53 - 00003588 _____ C:\WINDOWS\System32\Tasks\HuanjuGameUpdate
2017-06-20 20:49 - 2017-06-20 21:11 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2017-06-20 20:47 - 2017-06-20 20:47 - 00000000 ____D C:\Users\moxito\AppData\Local\PeerDistRepub
2017-06-20 20:41 - 2017-06-20 20:47 - 00000000 ____D C:\AdwCleaner
2017-06-20 20:41 - 2017-06-20 20:41 - 04110280 _____ C:\Users\moxito\Downloads\AdwCleaner_6.047.exe
2017-06-20 20:37 - 2017-06-20 20:37 - 00566128 _____ (Malwarebytes) C:\Users\moxito\Downloads\mbam-clean-2.3.0.1001.exe
2017-06-19 17:59 - 2017-06-19 17:59 - 00187408 _____ C:\WINDOWS\jUaJ.tIEvC
2017-06-19 17:59 - 2017-06-19 17:59 - 00106512 _____ C:\WINDOWS\HMOuyegwd9.Xw2Am
2017-06-19 02:52 - 2017-06-19 02:52 - 00143376 _____ C:\WINDOWS\59.T477k
2017-06-18 21:33 - 2017-06-18 21:33 - 00002811 _____ C:\Users\moxito\Desktop\RtkNGUI64.exe - Verknüpfung.lnk
2017-06-18 21:19 - 2017-06-18 21:27 - 00000000 ____D C:\Users\moxito\Desktop\Software & Treiber
2017-06-18 20:46 - 2017-06-18 20:46 - 00000000 ____D C:\ProgramData\Nahimic22.3.14
2017-06-18 20:34 - 2017-06-18 20:34 - 00450352 _____ (Microsoft Corporation) C:\Users\moxito\Downloads\FixitCenter_Run.exe
2017-06-18 20:31 - 2017-06-18 20:31 - 15549025 _____ C:\Users\moxito\Downloads\Microsoft_Fix-it-Paket.zip
2017-06-18 20:25 - 2017-06-18 20:25 - 00271376 _____ C:\WINDOWS\jaA3nrCQa91Ph1W.68S97
2017-06-18 19:59 - 2017-04-21 23:53 - 00029376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
2017-06-18 19:59 - 2017-04-21 23:53 - 00018600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr100_clr0400.dll
2017-06-18 19:59 - 2017-04-21 23:50 - 00030912 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2017-06-18 19:59 - 2017-04-21 23:50 - 00018592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr100_clr0400.dll
2017-06-18 19:59 - 2017-04-11 20:27 - 00993632 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2017-06-18 19:59 - 2017-04-11 20:27 - 00690008 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp120_clr0400.dll
2017-06-18 19:59 - 2017-03-15 20:15 - 00987840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2017-06-18 19:59 - 2017-03-15 20:15 - 00485576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp120_clr0400.dll
2017-06-18 19:43 - 2017-06-18 19:44 - 02296696 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-06-18 18:48 - 2017-06-20 21:25 - 00000000 ____D C:\Users\moxito\AppData\Local\CrashDumps
2017-06-18 05:54 - 2017-06-18 05:54 - 00000000 ____D C:\Users\moxito\AppData\Local\Apps\2.0
2017-06-18 01:01 - 2017-06-20 21:29 - 00031834 _____ C:\Users\moxito\Desktop\FRST.txt
2017-06-18 00:17 - 2017-06-18 01:03 - 00074146 _____ C:\Users\moxito\Desktop\Addition.txt
2017-06-18 00:01 - 2017-06-18 00:01 - 02388709 _____ C:\HEADERS
2017-06-17 23:44 - 2017-06-17 23:47 - 00000000 ___HD C:\$WINDOWS.~BT
2017-06-17 23:30 - 2017-06-17 23:30 - 00000000 ____D C:\Program Files\Synaptics
2017-06-17 19:05 - 2017-06-17 19:25 - 00000000 ____D C:\ESD
2017-06-17 19:05 - 2017-06-17 19:05 - 00000000 ___HD C:\$Windows.~WS
2017-06-17 18:36 - 2017-06-17 18:36 - 00079064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\tvwoetih.sys
2017-06-17 16:43 - 2017-06-17 16:43 - 05265000 _____ C:\Users\moxito\Downloads\psiphon3.exe
2017-06-17 00:14 - 2017-06-20 21:29 - 00000000 ____D C:\FRST
2017-06-17 00:13 - 2017-06-20 21:28 - 02439680 _____ (Farbar) C:\Users\moxito\Desktop\FRST64.exe
2017-06-16 23:23 - 2017-06-16 23:25 - 00000000 ____D C:\WINDOWS\Minidump
2017-06-16 23:04 - 2017-06-16 23:04 - 09598376 _____ (Piriform Ltd) C:\Users\moxito\Downloads\ccsetup531.exe
2017-06-16 22:42 - 2017-06-16 22:42 - 00000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-06-16 22:07 - 2017-06-16 22:07 - 00003654 _____ C:\WINDOWS\System32\Tasks\Dragon_Center_updater
2017-06-16 22:07 - 2017-06-16 22:07 - 00003016 _____ C:\WINDOWS\System32\Tasks\MSI_Dragon Center
2017-06-16 19:06 - 2017-06-16 19:06 - 81963976 _____ C:\Users\moxito\Downloads\SteelSeriesEngine3.10.2Setup.exe
2017-06-16 17:59 - 2017-06-03 11:23 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-06-16 17:59 - 2017-06-03 11:22 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcorehc.dll
2017-06-16 17:58 - 2017-06-03 12:50 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-06-16 17:58 - 2017-06-03 12:50 - 00192856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-06-16 17:58 - 2017-06-03 12:11 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-06-16 17:58 - 2017-06-03 12:06 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-06-16 17:58 - 2017-06-03 11:58 - 00340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-06-16 17:58 - 2017-06-03 11:55 - 00780640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-06-16 17:58 - 2017-06-03 11:52 - 01021784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-06-16 17:58 - 2017-06-03 11:52 - 00607072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-06-16 17:58 - 2017-06-03 11:52 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-06-16 17:58 - 2017-06-03 11:49 - 20967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-06-16 17:58 - 2017-06-03 11:44 - 01412640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-06-16 17:58 - 2017-06-03 11:44 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-06-16 17:58 - 2017-06-03 11:39 - 05686272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-06-16 17:58 - 2017-06-03 11:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-06-16 17:58 - 2017-06-03 11:32 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-06-16 17:58 - 2017-06-03 11:31 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-06-16 17:58 - 2017-06-03 11:31 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-06-16 17:58 - 2017-06-03 11:28 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-06-16 17:58 - 2017-06-03 11:28 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-06-16 17:58 - 2017-06-03 11:26 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-06-16 17:58 - 2017-06-03 11:26 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBrokerUI.dll
2017-06-16 17:58 - 2017-06-03 11:22 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-06-16 17:58 - 2017-06-03 11:22 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2017-06-16 17:58 - 2017-06-03 11:20 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-06-16 17:58 - 2017-06-03 11:19 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2017-06-16 17:58 - 2017-06-03 11:16 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-06-16 17:58 - 2017-06-03 11:15 - 19414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-06-16 17:58 - 2017-06-03 11:15 - 18364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-06-16 17:58 - 2017-06-03 11:15 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-06-16 17:58 - 2017-06-03 11:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2017-06-16 17:58 - 2017-06-03 11:08 - 12187648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-06-16 17:58 - 2017-06-03 11:08 - 02643968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-06-16 17:58 - 2017-06-03 11:08 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-06-16 17:58 - 2017-06-03 11:06 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-06-16 17:58 - 2017-06-03 11:05 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-06-16 17:58 - 2017-06-03 11:05 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2017-06-16 17:58 - 2017-06-03 11:04 - 06042624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-06-16 17:58 - 2017-06-03 11:04 - 02006528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-06-16 17:58 - 2017-06-03 11:04 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-06-16 17:58 - 2017-06-03 11:03 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-06-16 17:58 - 2017-06-03 11:02 - 02997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-06-16 17:58 - 2017-06-03 10:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-06-16 17:58 - 2017-03-04 08:22 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-06-16 17:58 - 2017-03-04 08:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-06-16 17:58 - 2017-03-04 08:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-06-16 17:58 - 2016-09-07 06:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2017-06-16 17:53 - 2017-06-03 11:14 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-06-16 17:53 - 2017-06-03 10:52 - 03403264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-06-16 17:53 - 2017-06-03 10:50 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-06-16 17:53 - 2017-06-03 10:49 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-06-16 17:52 - 2017-06-03 12:14 - 00136024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-06-16 17:52 - 2017-06-03 12:11 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-06-16 17:52 - 2017-06-03 12:09 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-06-16 17:52 - 2017-06-03 12:08 - 07783256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-06-16 17:52 - 2017-06-03 11:59 - 01181024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-06-16 17:52 - 2017-06-03 11:59 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-06-16 17:52 - 2017-06-03 11:53 - 00404824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-06-16 17:52 - 2017-06-03 11:51 - 02187104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-06-16 17:52 - 2017-06-03 11:51 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-06-16 17:52 - 2017-06-03 11:50 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-06-16 17:52 - 2017-06-03 11:49 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-06-16 17:52 - 2017-06-03 11:49 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-06-16 17:52 - 2017-06-03 11:48 - 00857952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-06-16 17:52 - 2017-06-03 11:48 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-06-16 17:52 - 2017-06-03 11:45 - 22220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-06-16 17:52 - 2017-06-03 11:44 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-06-16 17:52 - 2017-06-03 11:39 - 02532192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-06-16 17:52 - 2017-06-03 11:16 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-06-16 17:52 - 2017-06-03 11:15 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-06-16 17:52 - 2017-06-03 11:14 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-06-16 17:52 - 2017-06-03 11:14 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-06-16 17:52 - 2017-06-03 11:11 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-06-16 17:52 - 2017-06-03 11:10 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-06-16 17:52 - 2017-06-03 11:10 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBrokerUI.dll
2017-06-16 17:52 - 2017-06-03 11:09 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-06-16 17:52 - 2017-06-03 11:09 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcorehc.dll
2017-06-16 17:52 - 2017-06-03 11:09 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-06-16 17:52 - 2017-06-03 11:08 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-06-16 17:52 - 2017-06-03 11:07 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-06-16 17:52 - 2017-06-03 11:07 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-06-16 17:52 - 2017-06-03 11:03 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-06-16 17:52 - 2017-06-03 10:56 - 13091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-06-16 17:52 - 2017-06-03 10:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-06-16 17:52 - 2017-06-03 10:53 - 08125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-06-16 17:52 - 2017-06-03 10:52 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-06-16 17:52 - 2017-06-03 10:51 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-06-16 17:52 - 2017-06-03 10:50 - 04744704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-06-16 17:52 - 2017-06-03 10:49 - 03615744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-06-16 17:52 - 2017-06-03 10:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-06-16 17:52 - 2017-06-03 10:49 - 02318848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-06-16 17:52 - 2017-06-03 10:49 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-06-16 17:52 - 2017-06-03 10:48 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-06-16 17:52 - 2017-06-03 10:48 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-06-16 17:52 - 2017-06-03 10:48 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-06-16 17:52 - 2017-06-03 10:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-06-16 17:52 - 2017-06-03 10:46 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-06-16 17:52 - 2017-05-25 07:56 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-06-16 17:52 - 2017-03-04 08:16 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2017-06-16 17:51 - 2017-06-03 12:16 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-06-16 17:51 - 2017-06-03 12:14 - 01564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 01214816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 00629088 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 00544096 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 00334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 00233824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-06-16 17:51 - 2017-06-03 12:14 - 00096608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-06-16 17:51 - 2017-06-03 12:14 - 00034648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-06-16 17:51 - 2017-06-03 12:01 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-06-16 17:51 - 2017-06-03 11:59 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-06-16 17:51 - 2017-06-03 11:54 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-06-16 17:51 - 2017-06-03 11:50 - 00381792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-06-16 17:51 - 2017-06-03 11:48 - 01112416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2017-06-16 17:51 - 2017-06-03 11:48 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-06-16 17:51 - 2017-06-03 11:48 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-06-16 17:51 - 2017-06-03 11:40 - 01566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-06-16 17:51 - 2017-06-03 11:40 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-06-16 17:51 - 2017-06-03 11:39 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-06-16 17:51 - 2017-06-03 11:22 - 07217152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-06-16 17:51 - 2017-06-03 11:18 - 22569984 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-06-16 17:51 - 2017-06-03 11:16 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-06-16 17:51 - 2017-06-03 11:15 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-06-16 17:51 - 2017-06-03 11:14 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-06-16 17:51 - 2017-06-03 11:10 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-06-16 17:51 - 2017-06-03 11:08 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-06-16 17:51 - 2017-06-03 11:08 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-06-16 17:51 - 2017-06-03 11:07 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HNetCfgClient.dll
2017-06-16 17:51 - 2017-06-03 11:06 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-06-16 17:51 - 2017-06-03 11:01 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-06-16 17:51 - 2017-06-03 11:00 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-06-16 17:51 - 2017-06-03 10:58 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-06-16 17:51 - 2017-06-03 10:52 - 00975872 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-06-16 17:51 - 2017-06-03 10:52 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-06-16 17:51 - 2017-06-03 10:51 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2017-06-16 17:51 - 2017-06-03 10:49 - 02475520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-06-16 17:51 - 2017-06-03 10:49 - 01845248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-06-16 17:51 - 2017-06-03 10:49 - 00351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2017-06-16 17:51 - 2017-06-03 08:08 - 00080078 _____ C:\WINDOWS\system32\normidna.nls
2017-06-06 00:55 - 2017-06-06 00:55 - 00000000 ____D C:\Users\moxito\AppData\Roaming\RenewSoftware.com
2017-06-06 00:04 - 2017-06-06 00:04 - 4083853312 _____ C:\Users\moxito\Downloads\Win10_English_x64.iso
2017-06-05 23:23 - 2017-06-05 23:23 - 00004184 _____ C:\WINDOWS\System32\Tasks\{ED9A9CD4-5A31-2B7F-2D3D-2F4634FF2C3B}
2017-06-05 23:23 - 2017-06-05 23:23 - 00003884 _____ C:\WINDOWS\System32\Tasks\{F7B708E3-B402-CC93-0235-FB6400AF3F41}
2017-06-05 23:22 - 2017-06-05 23:22 - 01611944 _____ (Secure Download Ltd. ) C:\Users\moxito\Downloads\Registry_Activation
2017-06-05 23:21 - 2017-06-05 23:21 - 00000000 ____D C:\ProgramData\Caphyon
2017-05-24 16:31 - 2017-05-24 16:31 - 00187408 _____ C:\WINDOWS\3LQJZeRfB62pV.9W5pn
2017-05-24 16:31 - 2017-05-24 16:31 - 00053264 _____ C:\WINDOWS\FXu4.S5k12
2017-05-24 16:29 - 2017-05-18 07:21 - 00134592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2017-05-24 16:26 - 2017-05-18 09:35 - 40201848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 35390072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 35282040 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 28624504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 11056456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 11028664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 10551072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 09248144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 09014976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 08808488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 03797112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 03256440 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 01988216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438233.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 01606592 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438233.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 01278528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 01275944 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 01056704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00995736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00993912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00993872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00964032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00914880 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00775864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00725112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00688968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00618928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00612272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00609728 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00583800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00577728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-05-24 16:26 - 2017-05-18 09:35 - 00499320 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-05-22 21:10 - 2017-05-22 21:10 - 00095248 _____ C:\WINDOWS\Yfn76w2d9ICq.19CwO
2017-05-22 16:08 - 2017-05-22 16:08 - 00163856 _____ C:\WINDOWS\ok9734e.2DWmr
2017-05-22 00:22 - 2017-05-22 00:22 - 00001101 _____ C:\Users\moxito\Desktop\百度网盘.lnk
2017-05-22 00:22 - 2017-05-22 00:22 - 00000000 ____D C:\Users\moxito\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\百度网盘
2017-05-21 22:53 - 2017-05-21 22:53 - 00004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-21 22:53 - 2017-05-03 22:21 - 00175736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-05-21 22:53 - 2017-05-03 22:21 - 00143480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-05-21 22:32 - 2017-05-21 22:32 - 00000000 ____D C:\Users\moxito\AppData\Roaming\BaiduYunKernel
2017-05-21 22:32 - 2017-05-21 22:32 - 00000000 ____D C:\Users\moxito\AppData\Roaming\BaiduYunGuanjia
2017-05-21 20:51 - 2017-05-21 20:51 - 00002116 _____ C:\Users\Public\Desktop\Nahimic 2.lnk
2017-05-21 20:51 - 2017-05-21 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nahimic 2
2017-05-21 20:51 - 2017-05-21 20:51 - 00000000 ____D C:\Program Files\Nahimic
2017-05-21 20:51 - 2017-02-06 10:31 - 72520712 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2017-05-21 20:51 - 2017-02-06 10:31 - 10187598 _____ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2017-05-21 20:51 - 2017-02-06 10:31 - 03503048 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 03410832 _____ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 03299816 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 03203584 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 03122656 _____ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 03014656 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2017-05-21 20:51 - 2017-02-06 10:31 - 02830480 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 02190984 _____ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 01435136 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 01382232 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 01353816 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 01337640 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 01003504 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00984912 _____ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00965024 _____ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00962120 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00873456 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00866088 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00859912 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00855232 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00726624 _____ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00689880 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00601144 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00532376 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00517504 _____ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00467152 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00447176 _____ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00387312 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00381408 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00343704 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00341144 _____ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00341144 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00321712 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00321712 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00258856 _____ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00231912 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00221968 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00214824 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00209536 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00192976 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00166200 _____ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00158688 _____ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00110976 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00090912 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00088344 _____ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00088320 _____ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00083624 _____ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2017-05-21 20:51 - 2017-02-06 10:31 - 00075536 _____ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 07172912 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 07096184 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 06264632 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 05593608 _____ (Nahimic Inc) C:\WINDOWS\system32\NAHIMICAPOlfx.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 05347000 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 02444688 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 02202624 _____ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 01965808 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 01959600 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 01780616 _____ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 01591056 _____ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 01508928 _____ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 01133584 _____ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 01003856 _____ (Nahimic Inc) C:\WINDOWS\system32\NahimicAPONSControl.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00743960 _____ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00727432 _____ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00708304 _____ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00680512 _____ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00504304 _____ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00447712 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00445392 _____ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00441264 _____ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00416504 _____ (Harman) C:\WINDOWS\system32\HMUI.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00378384 _____ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00366120 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00362048 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00360344 _____ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00327448 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00310416 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00272712 _____ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00253896 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00253856 _____ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00252872 _____ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00203832 _____ (Harman) C:\WINDOWS\system32\HMHVS.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00190928 _____ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00190928 _____ (Harman) C:\WINDOWS\system32\HMEQ.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00179592 _____ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00154360 _____ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00151784 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00134192 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00122312 _____ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00118584 _____ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00105304 _____ C:\WINDOWS\system32\audioLibVc.dll
2017-05-21 20:51 - 2017-02-06 10:30 - 00084608 _____ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-20 21:26 - 2016-12-01 02:10 - 00000000 ____D C:\Users\moxito\AppData\LocalLow\SogouPY
2017-06-20 21:25 - 2016-11-25 00:46 - 00002094 _____ C:\Users\Public\Desktop\Tencent QQ.lnk
2017-06-20 21:25 - 2016-08-21 20:02 - 00000000 ____D C:\Users\moxito\Documents\Tencent Files
2017-06-20 21:23 - 2016-08-21 20:02 - 00018760 _____ C:\WINDOWS\SysWOW64\QQVistaHelper.dll
2017-06-20 21:16 - 2016-08-21 16:12 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-20 21:15 - 2016-11-25 16:32 - 00000000 ____D C:\Users\moxito\AppData\Roaming\The Bat!
2017-06-20 21:15 - 2016-10-11 11:04 - 03399696 _____ C:\WINDOWS\system32\perfh007.dat
2017-06-20 21:15 - 2016-10-11 11:04 - 00957568 _____ C:\WINDOWS\system32\perfc007.dat
2017-06-20 21:15 - 2016-08-21 17:36 - 00000000 ____D C:\Users\moxito\AppData\Local\Sidebar7
2017-06-20 21:15 - 2016-08-21 15:19 - 07127782 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-06-20 21:14 - 2016-10-30 02:17 - 00000040 ___SH C:\ProgramData\.zreglib
2017-06-20 21:11 - 2016-11-27 00:25 - 00000000 ____D C:\ProgramData\VMware
2017-06-20 21:11 - 2016-10-11 01:13 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-20 21:00 - 2016-12-01 02:10 - 00000000 ____D C:\Program Files (x86)\SogouInput
2017-06-20 20:49 - 2016-07-16 08:04 - 00262144 _____ C:\WINDOWS\system32\config\BBI
2017-06-20 20:47 - 2016-10-11 12:58 - 00000000 ____D C:\WINDOWS\system32\log
2017-06-20 20:47 - 2016-09-28 17:46 - 00000008 __RSH C:\ProgramData\ntuser.pol
2017-06-20 20:47 - 2016-07-16 13:45 - 00000000 ____D C:\WINDOWS\INF
2017-06-20 20:37 - 2016-10-11 01:10 - 00000000 ____D C:\Users\moxito
2017-06-20 20:36 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-20 20:36 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-20 05:32 - 2016-10-11 01:08 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-06-18 20:48 - 2016-10-11 01:13 - 00002502 _____ C:\WINDOWS\System32\Tasks\MSI_Dragon Gaming Center
2017-06-18 20:37 - 2016-08-21 17:10 - 00000000 ____D C:\Users\moxito\AppData\Local\ClassicShell
2017-06-18 20:00 - 2016-07-16 13:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-18 19:55 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-06-18 19:46 - 2016-08-21 22:03 - 00000000 ____D C:\Users\moxito\AppData\Roaming\vlc
2017-06-18 02:17 - 2017-04-26 02:17 - 20645376 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2017-06-18 02:17 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-06-18 00:37 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\Performance
2017-06-17 23:55 - 2016-10-11 01:14 - 00003780 _____ C:\WINDOWS\diagwrn.xml
2017-06-17 23:55 - 2016-10-11 01:14 - 00001908 _____ C:\WINDOWS\diagerr.xml
2017-06-17 23:47 - 2016-10-13 18:41 - 00000000 ____D C:\WINDOWS\Panther
2017-06-17 23:20 - 2016-08-21 17:08 - 00000000 ____D C:\ProgramData\BavSvc_exe
2017-06-17 22:41 - 2017-02-11 13:53 - 00000000 ____D C:\Users\moxito\AppData\Roaming\XnView
2017-06-17 19:58 - 2016-12-01 01:43 - 00000000 ____D C:\Users\moxito\Downloads\div. Windows
2017-06-17 18:56 - 2016-11-29 18:50 - 00000000 ____D C:\Users\moxito\AppData\Roaming\Psiphon3
2017-06-17 18:29 - 2016-11-29 18:50 - 05265000 _____ C:\Users\moxito\psiphon3.exe
2017-06-17 02:44 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\rescache
2017-06-17 02:12 - 2016-08-21 17:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-06-16 23:36 - 2016-08-21 16:55 - 00000000 ____D C:\Users\moxito\AppData\Roaming\steelseries-engine-3-client
2017-06-16 23:29 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-06-16 23:18 - 2016-11-25 00:13 - 00000000 ____D C:\ProgramData\Hauppauge
2017-06-16 23:08 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\tracing
2017-06-16 23:04 - 2016-08-21 16:58 - 00000823 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-06-16 23:02 - 2016-10-11 01:13 - 00002220 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-06-16 22:45 - 2016-08-21 15:17 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-06-16 22:43 - 2016-09-28 18:06 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-06-16 22:43 - 2016-09-28 18:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-06-16 22:42 - 2016-07-16 13:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-06-16 22:42 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-16 22:42 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-06-16 22:39 - 2016-11-25 17:35 - 00000000 ____D C:\Users\moxito\AppData\Roaming\uTorrent
2017-06-16 22:17 - 2016-08-21 15:41 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-06-16 22:15 - 2016-09-28 18:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-06-16 22:15 - 2016-08-21 15:41 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-06-16 22:08 - 2016-09-27 14:20 - 00000000 ____D C:\ProgramData\MSI
2017-06-16 22:07 - 2016-09-27 14:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2017-06-16 22:07 - 2016-08-21 16:30 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-06-16 19:08 - 2016-08-21 16:53 - 00000000 ____D C:\WINDOWS\Cnxt
2017-06-16 19:07 - 2016-08-21 16:53 - 00000000 ____D C:\ProgramData\Conexant
2017-06-16 15:49 - 2017-04-25 19:16 - 00000000 ____D C:\Program Files (x86)\YY
2017-06-06 00:36 - 2016-10-12 17:33 - 00000000 ____D C:\WINDOWS\PCHEALTH
2017-06-06 00:35 - 2016-08-22 16:31 - 00000000 ____D C:\Program Files (x86)\FormatFactory
2017-06-05 23:35 - 2016-12-15 05:59 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-06-05 23:34 - 2016-12-11 17:10 - 00000000 ____D C:\Program Files (x86)\Intel
2017-06-05 23:33 - 2016-09-27 14:09 - 00000000 ____D C:\Program Files (x86)\MSI
2017-06-03 08:36 - 2016-07-16 13:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-06-03 08:36 - 2016-07-16 13:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-05-24 16:29 - 2016-10-11 01:09 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-05-24 16:29 - 2016-09-15 19:33 - 00000000 ____D C:\Temp
2017-05-24 16:18 - 2016-09-28 16:42 - 00000000 ____D C:\Users\moxito\Documents\temp
2017-05-21 22:53 - 2017-02-07 15:54 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-21 22:53 - 2016-12-15 05:53 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-21 22:53 - 2016-10-11 01:13 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-21 22:53 - 2016-10-11 01:13 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-21 22:53 - 2016-10-11 01:13 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-21 22:53 - 2016-10-11 01:13 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-21 22:53 - 2016-10-11 01:13 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-21 22:53 - 2016-10-11 01:09 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-05-21 22:53 - 2016-09-27 13:26 - 00001449 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-05-21 22:53 - 2016-08-21 15:39 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-05-21 22:32 - 2016-08-22 17:03 - 00000000 ____D C:\Users\moxito\AppData\Roaming\baidu
2017-05-21 20:51 - 2016-10-11 01:09 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-05-21 20:51 - 2016-10-11 01:09 - 00000000 ____D C:\WINDOWS\system32\DAX2
2017-05-21 20:51 - 2016-08-21 15:43 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-21 20:48 - 2016-07-16 13:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
==================== Files in the root of some directories =======
2016-10-08 00:26 - 2016-10-08 00:29 - 0000752 _____ () C:\Users\moxito\AppData\Roaming\.emacs
2016-11-30 19:44 - 2016-11-30 19:44 - 0000020 _____ () C:\Users\moxito\AppData\Roaming\004D5649544E41696E66
2016-11-30 19:43 - 2016-11-30 19:43 - 0000256 _____ () C:\Users\moxito\AppData\Roaming\140A0027000007
2016-12-05 20:22 - 2016-12-05 20:22 - 0000024 _____ () C:\Users\moxito\AppData\Roaming\D3D5D3C0-0F3D-40c1-9973-CEB7C072AE31.ini
2016-11-30 19:44 - 2017-01-16 21:48 - 0001209 _____ () C:\Users\moxito\AppData\Roaming\D3D5D3C0-0F3D-40c1-9973-CEB7C072AE32.ini
2017-02-13 02:41 - 2017-02-13 02:41 - 0001038 _____ () C:\Users\moxito\AppData\Roaming\ex_log.txt
2016-10-10 20:08 - 2017-02-04 16:04 - 0001269 _____ () C:\Users\moxito\AppData\Roaming\Network Meter_Settings.ini
2016-10-10 20:09 - 2016-10-10 20:09 - 0000772 _____ () C:\Users\moxito\AppData\Roaming\Stock Meter_Settings.ini
2016-09-30 18:39 - 2016-10-10 19:53 - 0000122 _____ () C:\Users\moxito\AppData\Roaming\System Monitor II_UptimeRecord.ini
2017-01-28 01:25 - 2017-01-28 01:25 - 1444872 _____ (Tencent Inc.) C:\Users\moxito\AppData\Roaming\XQ4Q.DLL
2016-10-30 02:17 - 2017-06-20 21:14 - 0000040 ___SH () C:\ProgramData\.zreglib
2016-10-11 01:09 - 2016-10-11 01:09 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-01-28 03:09 - 2017-01-28 03:09 - 0076168 _____ (Tencent) C:\ProgramData\fa5HvkT6.aIj
2016-12-15 05:53 - 2017-01-18 15:10 - 0005110 _____ () C:\ProgramData\NvTelemetryContainer.log
2016-12-15 05:53 - 2017-01-14 12:59 - 0005110 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1
2016-11-24 23:00 - 2016-11-24 23:01 - 1696960 _____ () C:\ProgramData\QQGAMEQCK2119.DLL
2016-12-05 20:10 - 2016-12-05 20:10 - 1696960 _____ () C:\ProgramData\QQGAMEQCK2205.DLL
2016-12-04 20:08 - 2016-12-08 20:16 - 1389760 _____ () C:\ProgramData\QQGameQCK2840.exe
2017-01-28 01:29 - 2017-01-28 01:29 - 0076168 _____ (Tencent) C:\ProgramData\rW2F6Ma7N5GJI83.971
Files to move or delete:
====================
C:\ProgramData\QQGAMEQCK2119.DLL
C:\ProgramData\QQGAMEQCK2205.DLL
C:\ProgramData\QQGameQCK2840.exe
C:\Users\moxito\psiphon3.exe
Some files in TEMP:
====================
2017-06-20 21:29 - 2017-06-20 21:29 - 0031096 _____ (Tencent) C:\Users\moxito\AppData\Local\Temp\qqsafeud.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-19 02:49
==================== End of FRST.txt ============================ --- --- ---
--- --- --- |