Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-05-2017
Ran by Darryl (administrator) on DARYL-PC (11-05-2017 13:46:58)
Running from C:\Users\Darryl\Downloads
Loaded Profiles: Darryl (Available Profiles: Darryl)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(VoiceFive, Inc.) C:\Program Files (x86)\PremierOpinion\pmservice.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.SmartMonitor.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Device Integrator\wldi.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Live\Device Integrator\DI_HIDServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe
HKLM\...\Run: [Persistence] => C:\Windows\system32\igfxpers.exe
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\...\Run: [WindowsLiveDeviceIntegrator] => C:\Program Files (x86)\Windows Live\Device Integrator\wldi.exe [245544 2010-09-24] (Microsoft Corporation)
HKLM-x32\...\Run: [tvncontrol] => "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\...\MountPoints2: {7381b751-215b-11e6-b813-806e6f6e6963} - D:\Bin\Instv2.exe
Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{32168274-7FAD-488F-8B52-F84235607655}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{59C24924-C494-4126-83E7-06B8FA81FDC0}: [DhcpNameServer] 192.168.0.33 192.168.0.35 192.168.0.48
Tcpip\..\Interfaces\{768B4AA3-8550-4F25-81F5-A41CB87974CB}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{8EECCB24-0617-42D6-A07D-C116CD0FAD50}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{91CFFC6B-4C5F-4937-AF63-A585CFF7D819}: [NameServer] 192.168.1.1
Tcpip\..\Interfaces\{A93B07B1-50F2-41C7-B151-66390C5FD36B}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{CE3B93E3-F59D-4AB3-BEDB-A05D2999B530}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://k2b-bulk.ebay.com.au/ws/eBayISAP ... e=LCActive
HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://ninemsn.com.au/?ocid=iehp
HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.quicksales.com.au/secure/Use ... statusid=2
hxxps://www.facebook.com/groups/dublin. ... ctivity#!/
hxxp://www.biblegateway.com/
hxxp://www.news.com.au/breaking-news
hxxps://outlook.office365.com/owa/?exsv ... path=/mail
SearchScopes: HKU\.DEFAULT -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> {10B4E706-0FB5-43BE-88B2-C3CC5CCFECC8} URL = hxxp://search.surfcanyon.com/search?f=sb&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q={searchTerms}&src=IE-SearchBox
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-04-26] (Intel Security)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26] (SEIKO EPSON CORPORATION)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-05] (Google Inc.)
BHO-x32: IE7Pro BHO -> {00011268-E188-40DF-A514-835FCD78B1BF} -> C:\Program Files (x86)\IEPro\iepro.dll [2010-06-02] (IE7Pro.com)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-04-26] (Intel Security)
BHO-x32: Fast Search -> {5AB7104A-B71F-49AD-9154-F7F8806AE848} -> C:\Program Files (x86)\Surf Canyon\surfcanyon.dll [2012-06-26] (Surf Canyon Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-08-22] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-05] (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-08-22] (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll [2011-01-26] (SEIKO EPSON CORPORATION)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-05] (Google Inc.)
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll [2017-04-26] (Intel Security)
Toolbar: HKLM-x32 - Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\IEPro\IEProRecorder.dll [2010-06-02] ()
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-05] (Google Inc.)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-04-26] (Intel Security)
Toolbar: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
Toolbar: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-05] (Google Inc.)
Toolbar: HKU\S-1-5-21-3954687424-2891801135-1833679319-1000 -> No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - No File
DPF: HKLM {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net ... plugin.cab
DPF: HKLM {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://javadl-esd.sun.com/update/1.5.0/ ... s-i586.cab
DPF: HKLM-x32 {0742B9EF-8C83-41CA-BFBA-830A59E23533} hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: HKLM-x32 {38AB0814-B09B-4378-9940-14A19638C3C2} hxxp://merchant.auctivacommerce.com/js/ ... ader57.cab
DPF: HKLM-x32 {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} hxxp://www.oztion.com.au/WebResource.ax ... 2182260000
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: HKLM-x32 {EE1FA3D5-2E0E-4D14-B9B4-7C81DEB58A46} hxxp://www.auctiva.com/Aurigma/8.0.49/Uploader8.cab
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll [2010-05-05] (Belarc, Inc.)
FireFox:
========
FF ProfilePath: C:\Users\Darryl\AppData\Roaming\TomTom\HOME\Profiles\1jil5pi8.default [2016-06-17]
FF Extension: (Emulator) - C:\Users\Darryl\AppData\Roaming\TomTom\HOME\Profiles\1jil5pi8.default\Extensions\Navcore.9.510.1234792@tomtom.com [2016-06-17] [not signed]
FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2016-06-17] [not signed]
FF ProfilePath: C:\Users\Darryl\AppData\Roaming\Mozilla\Firefox\Profiles\aaxirjbo.default [2017-04-20]
FF NewTab: Mozilla\Firefox\Profiles\aaxirjbo.default -> http://www.google.com
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\aaxirjbo.default -> Bing
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\aaxirjbo.default -> Bing
FF Homepage: Mozilla\Firefox\Profiles\aaxirjbo.default -> hxxp://k2b-bulk.ebay.com.au/ws/eBayISAP ... e=LCActive
hxxp://www.quicksales.com.au/secure/use ... statusid=2
hxxps://www.facebook.com/
FF Keyword.URL: Mozilla\Firefox\Profiles\aaxirjbo.default -> hxxp://www.bing.com/search?FORM=SK2MDF&PC=SK2M&q=
FF Extension: (Bing Search) - C:\Users\Darryl\AppData\Roaming\Mozilla\Firefox\Profiles\aaxirjbo.default\Extensions\bingsearch.full@microsoft.com [2015-07-04] [not signed]
FF Extension: (Avira Password Manager) - C:\Users\Darryl\AppData\Roaming\Mozilla\Firefox\Profiles\aaxirjbo.default\Extensions\passwordmanager@avira.com [2017-04-20]
FF Extension: (Avira SafeSearch Plus) - C:\Users\Darryl\AppData\Roaming\Mozilla\Firefox\Profiles\aaxirjbo.default\Extensions\safesearchplus2@avira.com [2017-04-20]
FF ProfilePath: C:\Users\Darryl\AppData\Roaming\Flock\Browser\Profiles\r9aq44ne.default [2014-06-20]
FF SelectedSearchEngine: Flock\Browser\Profiles\r9aq44ne.default -> Yahoo
FF Homepage: Flock\Browser\Profiles\r9aq44ne.default -> hxxp://www.flock.com/photobucket/start/
FF Extension: (Skype Click to Call) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-10-08]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found
FF HKLM-x32\...\Firefox\Extensions: [{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}] - C:\Program Files (x86)\PremierOpinion\firefox
FF Extension: (PremierOpinion) - C:\Program Files (x86)\PremierOpinion\firefox [2017-05-10] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-08-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-08-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-08-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-06-22] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.4.53 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-06-22] (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-29] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll [2012-03-22] (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-27] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxps://signin.ebay.com.au/ws/eBayISAPI.dll?SignIn&UsingSSL=1&pUserId=&co_partnerId=2&siteid=15&ru=http%3A%2F%2Fk2b-bulk.ebay.com.au%2Fws%2FeBayISAPI.dll%3FListingConsole%26%26guest%3D1%26currentPage%3DLCActive%26guest%3D1&pageType=5468","hxxps://www.auctiva.com/signin.aspx","hxxps://www.facebook.com/","hxxp://www.symbols-n-emoticons.com/p/facebook-emoticons-list.html","hxxps://www.biblegateway.com/","hxxps://signon.telstra.com.au/login?goto=http%3A%2F%2Femail.telstra.com%3A443%2Fwebmail%2Fbin%2Fauth","hxxps://login.microsoftonline.com/common/oauth2/authorize?client_id=4345a7b9-9a63-4910-a426-35363201d503&response_mode=form_post&response_type=code+id_token&scope=openid+profile&state=OpenIdConnect.AuthenticationProperties%3dfKBDx9fO04YsbD2NrT1ePa7RGdH3EtgoWE7YfheIEyO3zzyOU7oeARaPBk-bZrdFY42I_2CxHkL5f4iB0Q8sdLaNz03nr-v35IjeoXcxermTg48J-2D-ZBRzF9O3br5Zu3Trtp6nseriLx50XrqEojSs6gVJom2aZeStiEO3vYAVH695dDHqqaCZSBi6VVTtwTYV6S5YOfUI7o8gHAHFzXcQAE4QodQw371p6qR7p6ybKBSWZUOg32yFWPiGIZ9Iv6ZKfDp06-pn3Smlq5CTh4nOAtK9CdgkYPgsZBDbRcY&nonce=636283272081392523.Yzk1MTFmNzgtNDUzOS00NjI0LWJkYTktMGNiZGJjYWJlMzk1MTcyNDkxZWEtMDBiNi00MTgzLTgwZTktOTZjNzA3MzEyOWFm&redirect_uri=https%3a%2f%2fwww.office.com%2flanding&ui_locales=en-AU&mkt=en-AU&client-request-id=56d6fe0f-cd40-4096-87c0-4b11aedfc291&msafed=0"
CHR NewTab: Default -> Not-active:"chrome-extension://hookklgbmgffgeefbnhhnbmcobhcgced/newtab/newtab.html"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM ... PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSuggestURL: Default -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en
CHR Profile: C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default [2017-05-11]
CHR Extension: (Avira Safe Shopping) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbpbkebodcjkknkfkpmfeciinhidaeh [2017-04-20]
CHR Extension: (The Dusty Arcade Ad) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\cocblbiaemimhlpgkadmmmpnbddjigph [2017-05-09]
CHR Extension: (History Button) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\fofpnhmbgmmeaialapfddhbhfongoinh [2014-01-22]
CHR Extension: (Weather Forecast Alerts) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\hookklgbmgffgeefbnhhnbmcobhcgced [2017-03-11]
CHR Extension: (Avira SafeSearch Plus) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2017-04-20]
CHR Extension: (eBay for Chrome) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\khhckppjhonfmcpegdjdibmngahahhck [2016-11-23]
CHR Extension: (PremierOpinion) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle [2017-05-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-11]
CHR Extension: (Chrome Media Router) - C:\Users\Darryl\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-05]
CHR HKLM\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3954687424-2891801135-1833679319-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [caljgklbbfbcjjanaijlacgncafpegll] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [mkndcbhcgphcfkkddanakjiepeknbgle] - C:\Program Files (x86)\PremierOpinion\pmcm.crx [2017-05-10]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2014-07-23] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-07-23] () [File not signed]
R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [662592 2014-08-03] (SEIKO EPSON CORPORATION)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [341984 2016-12-06] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2015-08-07] (Intel Corporation)
S3 KtmRm; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 KtmRm; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 PremierOpinion; C:\Program Files (x86)\PremierOpinion\pmservice.exe [204736 2017-03-14] (VoiceFive, Inc.) [File not signed] <==== ATTENTION
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-24] (StarWind Software) [File not signed]
R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [996736 2017-04-18] (McAfee, Inc.)
R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16160 2017-04-18] (McAfee, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [20520 2010-03-01] ()
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] ()
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [471496 2015-05-19] (Intel Corporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-03-22] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2015-07-29] (Intel Corporation)
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-05-11] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-05-11] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-05-11] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2017-05-11] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-05-11] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [178976 2015-07-28] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [503352 2010-12-29] () [File not signed]
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13920 2017-05-10] ()
S3 zgwhsdiag; C:\Windows\System32\DRIVERS\zgwhsdiag.sys [150656 2009-02-19] (ZTE Incorporated)
S3 zgwhsmdm; C:\Windows\System32\DRIVERS\zgwhsmdm.sys [150656 2009-02-19] (ZTE Incorporated)
U3 a4be0mt1; C:\Windows\System32\Drivers\a4be0mt1.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 DIRECTIO; \??\UNC\buildlab\Buildtools\BurnInTest_64\DirectIo.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S3 LVPr2M64; system32\DRIVERS\LVPr2M64.sys [X]
S3 massfilter_hs; \??\C:\Windows\system32\drivers\massfilter_hs.sys [X]
S3 zghsdiag; system32\DRIVERS\zghsdiag.sys [X]
S3 zghsmdm; system32\DRIVERS\zghsmdm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-11 12:33 - 2017-05-11 12:34 - 00047111 _____ C:\Users\Darryl\Downloads\Addition.txt
2017-05-11 12:32 - 2017-05-11 13:46 - 00027596 _____ C:\Users\Darryl\Downloads\FRST.txt
2017-05-11 12:31 - 2017-05-11 13:46 - 00000000 ____D C:\FRST
2017-05-11 12:30 - 2017-05-11 12:31 - 02429440 _____ (Farbar) C:\Users\Darryl\Downloads\FRST64.exe
2017-05-11 12:30 - 2017-05-11 12:30 - 01769984 _____ (Farbar) C:\Users\Darryl\Downloads\FRST.exe
2017-05-11 00:29 - 2017-05-11 09:24 - 00082720 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-05-11 00:29 - 2017-05-11 09:07 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-05-11 00:29 - 2017-05-11 09:07 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-05-11 00:29 - 2017-05-11 00:29 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-05-11 00:28 - 2017-05-11 09:07 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-05-11 00:28 - 2017-05-11 00:28 - 00001827 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-05-11 00:28 - 2017-05-11 00:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-05-11 00:28 - 2017-05-11 00:28 - 00000000 ____D C:\Program Files\Malwarebytes
2017-05-11 00:28 - 2017-03-22 11:02 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-05-11 00:26 - 2017-05-11 00:27 - 60107896 _____ (Malwarebytes ) C:\Users\Darryl\Downloads\mb3-setup-consumer-3.0.6.1469-10103.exe
2017-05-10 20:57 - 2017-05-10 20:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PremierOpinion
2017-05-10 08:54 - 2017-04-28 11:14 - 05547240 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-05-10 08:54 - 2017-04-28 11:14 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-05-10 08:54 - 2017-04-28 11:14 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-05-10 08:54 - 2017-04-28 11:14 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-05-10 08:54 - 2017-04-28 11:14 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-05-10 08:54 - 2017-04-28 11:11 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-05-10 08:54 - 2017-04-28 11:10 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 11:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:36 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-05-10 08:54 - 2017-04-28 10:36 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-05-10 08:54 - 2017-04-28 10:34 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:19 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-05-10 08:54 - 2017-04-28 10:19 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-05-10 08:54 - 2017-04-28 10:19 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-05-10 08:54 - 2017-04-28 10:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-05-10 08:54 - 2017-04-28 10:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-05-10 08:54 - 2017-04-28 10:14 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-05-10 08:54 - 2017-04-28 10:12 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-05-10 08:54 - 2017-04-28 10:11 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-05-10 08:54 - 2017-04-28 10:11 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-05-10 08:54 - 2017-04-28 10:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-05-10 08:54 - 2017-04-28 10:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-05-10 08:54 - 2017-04-28 10:10 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-05-10 08:54 - 2017-04-28 10:08 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-05-10 08:54 - 2017-04-28 10:08 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-05-10 08:54 - 2017-04-28 10:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-05-10 08:54 - 2017-04-28 10:08 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-05-10 08:54 - 2017-04-28 10:07 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-05-10 08:54 - 2017-04-28 10:07 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:07 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-05-10 08:54 - 2017-04-28 10:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-05-10 08:54 - 2017-04-27 00:59 - 03220992 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-05-10 08:54 - 2017-04-22 01:34 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-05-10 08:54 - 2017-04-22 01:15 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 00876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-05-10 08:54 - 2017-04-18 01:37 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-05-10 08:54 - 2017-04-18 01:12 - 01417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-05-10 08:54 - 2017-04-18 01:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-05-10 08:54 - 2017-04-18 01:12 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2017-05-10 08:54 - 2017-04-18 00:54 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2017-05-10 08:54 - 2017-04-13 01:32 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-05-10 08:54 - 2017-04-13 01:32 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-05-10 08:54 - 2017-04-13 01:32 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-05-10 08:54 - 2017-04-13 01:32 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-05-10 08:54 - 2017-04-13 01:26 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2017-05-10 08:54 - 2017-04-13 01:25 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-05-10 08:54 - 2017-04-13 01:25 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2017-05-10 08:54 - 2017-04-13 01:25 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2017-05-10 08:54 - 2017-04-08 01:34 - 00986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-05-10 08:54 - 2017-04-08 01:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-05-10 08:54 - 2017-04-08 01:30 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-05-10 08:54 - 2017-04-08 01:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-05-10 08:54 - 2017-04-08 01:22 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-05-10 08:54 - 2017-04-06 00:55 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-05-10 08:54 - 2017-04-06 00:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-05-10 08:54 - 2017-04-06 00:55 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-05-10 08:54 - 2017-04-05 01:34 - 01895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-05-10 08:54 - 2017-04-05 01:34 - 00377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-05-10 08:54 - 2017-04-05 01:34 - 00287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-05-10 08:54 - 2017-04-05 00:53 - 00496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-05-10 08:54 - 2017-04-05 00:53 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-05-10 08:54 - 2017-03-11 02:32 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-05-10 08:54 - 2017-03-11 02:32 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-05-10 08:54 - 2017-03-11 02:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-05-10 08:54 - 2017-03-11 02:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2017-05-10 08:54 - 2017-03-11 01:57 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-05-10 08:54 - 2017-03-11 01:55 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-05-10 08:54 - 2017-03-11 01:55 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-05-10 08:54 - 2017-03-10 02:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-05-10 08:54 - 2017-03-10 02:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-05-10 08:37 - 2017-05-10 16:55 - 00000000 ____D C:\Users\Darryl\Downloads\opera autoupdate
2017-05-10 08:33 - 2017-05-10 08:33 - 00000000 ____D C:\ProgramData\dbg
2017-05-10 08:31 - 2017-05-10 21:46 - 00000000 ____D C:\Users\Darryl\AppData\Local\SlimWare Utilities Inc
2017-05-10 08:31 - 2017-05-10 16:50 - 00013920 _____ C:\Windows\system32\Drivers\SWDUMon.sys
2017-05-09 23:51 - 2017-05-09 23:51 - 00001645 _____ C:\Users\Darryl\Desktop\Carinity.jpg - Shortcut.lnk
2017-05-09 18:02 - 2017-05-11 09:13 - 00000000 ____D C:\Program Files (x86)\PremierOpinion
2017-05-09 18:02 - 2017-05-09 18:02 - 00004286 _____ C:\Windows\System32\Tasks\Opera scheduled suite Autoupdate 1494316921
2017-05-09 18:02 - 2017-05-09 18:02 - 00004066 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1494316920
2017-05-09 18:02 - 2017-05-09 18:02 - 00000000 ____D C:\Users\Darryl\AppData\Roaming\Opera Software
2017-05-09 18:02 - 2017-05-09 18:02 - 00000000 ____D C:\Users\Darryl\AppData\Local\Opera Software
2017-05-09 18:01 - 2017-05-09 18:02 - 00000000 ____D C:\ProgramData\COMODO
2017-05-09 18:01 - 2017-05-09 18:01 - 00000000 ____D C:\Program Files\COMODO
2017-05-09 17:58 - 2017-05-09 17:58 - 00777411 _____ C:\Users\Darryl\Downloads\_FiveNightsAtFreddys_download.zip
2017-05-09 17:57 - 2017-05-09 17:57 - 01242128 _____ (Bekubicamo ) C:\Users\Darryl\Downloads\FiveNightsAtFreddys_download.exe
2017-05-08 19:29 - 2017-05-08 19:53 - 00001681 _____ C:\Users\Darryl\Desktop\it's a trap.jpeg - Shortcut.lnk
2017-05-08 19:28 - 2017-05-08 19:28 - 00040506 _____ C:\Users\Darryl\Documents\it's a trap.jpeg
2017-05-08 19:27 - 2017-05-08 19:27 - 00064771 _____ C:\Users\Darryl\Documents\e1509117d4b42527547953f2c7c4c966_admiral-ackbar-its-a-trap-meme-admiral-ackbar-its-a-trap-meme_853-480.jpeg
2017-05-08 16:12 - 2017-05-11 00:07 - 00000000 ____D C:\Users\Darryl\AppData\Local\tkdata
2017-05-08 16:11 - 2017-05-10 08:36 - 00001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Key.lnk
2017-05-08 16:11 - 2017-05-10 08:36 - 00001151 _____ C:\Users\Public\Desktop\True Key.lnk
2017-05-08 16:11 - 2017-05-08 16:11 - 00000000 ____D C:\ProgramData\TrueKey
2017-05-08 16:11 - 2017-05-08 16:11 - 00000000 ____D C:\Program Files\Intel Security
2017-05-08 16:09 - 2017-05-10 16:25 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-05-08 16:09 - 2017-05-08 16:09 - 00003344 _____ C:\Windows\System32\Tasks\McAfee Remediation (Prepare)
2017-05-08 16:09 - 2017-05-08 16:09 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-05-08 15:55 - 2017-05-10 20:02 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-05-08 15:55 - 2017-05-10 16:24 - 00000000 ____D C:\Program Files\TrueKey
2017-05-08 12:11 - 2017-05-08 12:11 - 00022357 _____ C:\Users\Darryl\Downloads\Receipt-3538012.pdf
2017-05-08 11:39 - 2017-05-08 11:39 - 00000000 ____D C:\Users\Darryl\AppData\Local\{F773F2D2-30C3-4008-8D2E-04B91644EC51}
2017-05-07 16:07 - 2017-05-08 19:55 - 00001794 _____ C:\Users\Darryl\Desktop\tasmaniabluecrossdemijohn.jpg - Shortcut.lnk
2017-05-06 19:00 - 2017-05-08 19:55 - 00001704 _____ C:\Users\Darryl\Desktop\anniversarydate.jpg - Shortcut.lnk
2017-05-05 09:51 - 2017-05-05 09:51 - 00011430 _____ C:\Users\Darryl\Downloads\CallsYetToBeBilled_Service_0412712186 (5).csv
2017-05-03 10:56 - 2017-05-03 10:56 - 00209810 _____ C:\Users\Darryl\Downloads\Hodgkinson Goldfields Geo Map 2.pdf
2017-05-03 10:55 - 2017-05-03 10:55 - 00153835 _____ C:\Users\Darryl\Downloads\Hodgkinson Goldfield Geo Map 1.pdf
2017-04-27 11:00 - 2017-05-05 10:58 - 00001650 _____ C:\Users\Darryl\Desktop\universal.jpg - Shortcut.lnk
2017-04-25 17:03 - 2017-05-05 10:58 - 00002065 _____ C:\Users\Darryl\Desktop\daryljudy.JPG - Shortcut.lnk
2017-04-22 17:08 - 2017-05-05 10:58 - 00001765 _____ C:\Users\Darryl\Desktop\cyclonetrackmapoverlay.jpeg - Shortcut.lnk
2017-04-22 13:17 - 2017-05-05 10:58 - 00001610 _____ C:\Users\Darryl\Desktop\2zge8.jpg - Shortcut.lnk
2017-04-21 21:07 - 2017-04-21 21:07 - 00000000 ____D C:\Users\Darryl\AppData\Local\{C00089DC-4914-4633-AB99-99B47714DC39}
2017-04-21 08:44 - 2017-04-21 08:44 - 00002062 _____ C:\Users\Darryl\Desktop\Free Antivirus Profile Quick scan.LNK
2017-04-21 08:37 - 2017-04-21 08:37 - 00000000 ____D C:\Users\Darryl\AppData\Local\CEF
2017-04-20 22:33 - 2017-04-20 22:33 - 00000000 ____D C:\Users\Darryl\AppData\Local\AviraSpeedup
2017-04-20 22:32 - 2017-04-20 22:32 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf
2017-04-20 22:16 - 2017-04-21 11:27 - 00000000 ____D C:\Users\Darryl\AppData\Local\Avira
2017-04-20 22:16 - 2017-04-20 22:16 - 00000000 ____D C:\Windows\System32\Tasks\Avira
2017-04-20 22:10 - 2017-04-20 22:10 - 04737440 _____ (Avira Operations GmbH & Co. KG) C:\Users\Darryl\Downloads\avira_en_fass0_58f8a4b11987a__ws.exe
2017-04-16 09:19 - 2017-04-16 09:19 - 00000000 ____D C:\Users\Darryl\AppData\Local\{B611D048-5CF0-4624-9E92-C5915CCB5516}
2017-04-15 23:26 - 2017-04-16 10:10 - 00001704 _____ C:\Users\Darryl\Desktop\Rosalie Frater2.jpg - Shortcut.lnk
2017-04-15 23:00 - 2017-04-15 23:00 - 00153930 _____ C:\Users\Darryl\Downloads\Harriet Cook GURR.pdf
2017-04-15 22:47 - 2017-04-16 10:10 - 00001969 _____ C:\Users\Darryl\Desktop\Rosalie Frater 5th from the right second row.jpg - Shortcut.lnk
2017-04-12 07:08 - 2017-03-23 01:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-04-12 07:08 - 2017-03-23 01:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-04-12 07:08 - 2017-03-23 01:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-04-12 07:08 - 2017-03-23 01:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-04-12 07:08 - 2017-03-23 01:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-12 07:08 - 2017-03-23 01:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-12 07:08 - 2017-03-23 01:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-12 07:08 - 2017-03-23 01:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-04-12 07:08 - 2017-03-23 01:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-04-12 07:08 - 2017-03-23 01:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-04-12 07:08 - 2017-03-23 01:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-04-12 07:08 - 2017-03-23 01:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-04-12 07:08 - 2017-03-23 01:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-12 07:08 - 2017-03-23 01:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-12 07:08 - 2017-03-23 01:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-04-12 07:08 - 2017-03-23 01:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-12 07:08 - 2017-03-11 02:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-04-12 07:08 - 2017-03-11 02:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-04-12 07:08 - 2017-03-11 02:31 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-04-12 07:08 - 2017-03-11 02:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-04-12 07:08 - 2017-03-11 02:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-04-12 07:08 - 2017-03-11 02:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-12 07:08 - 2017-03-11 02:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-04-12 07:08 - 2017-03-11 02:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-04-12 07:08 - 2017-03-11 02:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-04-12 07:08 - 2017-03-11 01:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-12 07:08 - 2017-03-08 02:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-04-12 07:08 - 2017-03-08 02:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-12 07:08 - 2017-03-08 00:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-04-12 07:08 - 2017-03-04 11:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-04-12 07:08 - 2017-03-04 11:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-04-12 07:08 - 2017-03-04 11:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-12 07:08 - 2017-03-04 11:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-12 07:08 - 2017-02-15 02:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-04-12 07:08 - 2017-02-15 02:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-04-12 07:08 - 2017-02-10 02:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-04-12 07:08 - 2017-02-10 02:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-04-12 07:08 - 2017-02-10 02:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-12 07:08 - 2017-01-19 01:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-12 07:08 - 2016-03-24 08:40 - 03181568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-04-12 07:08 - 2016-03-24 08:40 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-05-11 09:24 - 2014-05-20 12:12 - 24368414 _____ C:\Windows\ntbtlog.txt
2017-05-11 09:19 - 2009-07-14 14:45 - 00023376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-11 09:19 - 2009-07-14 14:45 - 00023376 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-11 09:16 - 2010-07-23 21:04 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-11 09:08 - 2016-05-26 10:35 - 00000000 __SHD C:\Users\Darryl\IntelGraphicsProfiles
2017-05-11 09:06 - 2009-07-14 15:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-11 00:48 - 2014-05-21 09:57 - 00000000 ____D C:\Users\Darryl\AppData\Local\CrashDumps
2017-05-11 00:28 - 2011-08-30 12:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-05-10 22:36 - 2011-01-19 12:26 - 00003930 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{F59818A2-D362-475B-81B4-C930E710F76C}
2017-05-10 21:52 - 2010-08-04 08:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2017-05-10 21:52 - 2010-08-04 08:31 - 00000000 ____D C:\ProgramData\WinZip
2017-05-10 21:48 - 2009-07-14 13:20 - 00000000 ____D C:\Windows\inf
2017-05-10 20:02 - 2012-07-25 17:20 - 00803320 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-05-10 20:02 - 2012-07-25 17:20 - 00144888 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-05-10 20:02 - 2012-07-25 17:20 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-05-10 20:02 - 2010-11-21 14:34 - 00000000 ____D C:\Windows\system32\Macromed
2017-05-10 20:02 - 2010-07-23 15:23 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-05-10 16:32 - 2009-07-14 15:13 - 00783288 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-10 16:25 - 2009-07-14 14:45 - 00321720 _____ C:\Windows\system32\FNTCACHE.DAT
2017-05-10 16:06 - 2010-09-11 21:02 - 00767154 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-05-10 16:04 - 2013-07-18 03:23 - 00000000 ____D C:\Windows\system32\MRT
2017-05-10 16:02 - 2010-07-23 16:13 - 156335152 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-05-10 08:37 - 2011-06-17 19:56 - 00000000 ____D C:\ProgramData\McAfee
2017-05-10 08:36 - 2010-07-21 15:31 - 00000000 ____D C:\Program Files\Common Files\Intel
2017-05-10 08:33 - 2009-07-14 15:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2017-05-09 17:59 - 2015-03-11 16:02 - 00000000 ____D C:\Users\Darryl\AppData\Local\Downloaded Installers
2017-05-08 16:12 - 2014-06-10 23:28 - 00000000 ____D C:\ProgramData\Intel
2017-05-08 16:10 - 2016-05-24 13:57 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-08 16:09 - 2015-07-04 18:31 - 00000000 ____D C:\Program Files\Common Files\AV
2017-05-08 15:56 - 2010-07-23 16:02 - 00000000 ____D C:\Users\Darryl\AppData\Local\Adobe
2017-05-07 10:13 - 2010-07-23 19:02 - 01398834 _____ C:\aqueduct.txt
2017-05-07 10:13 - 2010-07-23 19:01 - 00000082 _____ C:\Windows\MPLAYER.INI
2017-05-07 10:13 - 2010-07-23 19:00 - 00000000 ____D C:\FTW
2017-05-07 10:13 - 2009-07-14 12:34 - 00000434 _____ C:\Windows\win.ini
2017-05-05 19:39 - 2015-06-27 18:04 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-04-28 16:08 - 2010-07-23 21:01 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-28 16:08 - 2010-07-23 21:01 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-20 22:39 - 2015-10-23 21:39 - 00000000 ____D C:\Users\Darryl\AppData\Local\AvgSetupLog
2017-04-20 22:39 - 2011-01-09 14:36 - 00000000 ____D C:\Users\Darryl\AppData\Roaming\skypePM
2017-04-20 22:39 - 2011-01-09 14:33 - 00000000 ____D C:\Users\Darryl\AppData\Roaming\Skype
2017-04-20 22:39 - 2010-12-12 20:34 - 00000000 ____D C:\Program Files (x86)\TranslatorBar_3.3
2017-04-20 22:39 - 2010-10-01 21:16 - 00000000 ____D C:\Users\Darryl\AppData\LocalLow\Temp
2017-04-20 22:39 - 2010-10-01 21:16 - 00000000 ____D C:\Program Files (x86)\myBabylon_English
2017-04-20 22:39 - 2010-07-23 18:25 - 00000000 ___DC C:\Users\Darryl\AppData\Local\MigWiz
2017-04-20 22:39 - 2010-07-23 18:04 - 00000000 ____D C:\Users\Darryl\AppData\Roaming\TeamViewer
2017-04-20 22:39 - 2010-07-22 08:44 - 00000000 ____D C:\Windows\Panther
2017-04-20 22:16 - 2013-06-08 13:54 - 00073928 _____ C:\Users\Darryl\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-17 10:04 - 2009-07-14 15:08 - 00032612 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-16 10:20 - 2016-12-04 16:39 - 00000000 ____D C:\Users\Darryl\Desktop\DARIA
2017-04-13 10:26 - 2014-11-13 22:45 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-04-12 16:25 - 2012-05-12 21:15 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-12 16:25 - 2012-05-12 21:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-12 16:07 - 2012-05-12 21:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
==================== Files in the root of some directories =======
2010-07-23 23:21 - 2010-07-23 23:21 - 0000707 _____ () C:\Program Files (x86)\Canasta From Special K.LNK
2016-02-10 10:57 - 2016-02-10 10:57 - 0003072 _____ () C:\Program Files (x86)\http_canasta-from-special-k.software.informer.com_0.localstorage
2016-02-10 10:57 - 2016-02-10 10:57 - 0000000 _____ () C:\Program Files (x86)\http_canasta-from-special-k.software.informer.com_0.localstorage-journal
2015-02-25 16:42 - 2015-02-25 17:02 - 0000115 _____ () C:\Users\Darryl\AppData\Roaming\LogFile.txt
2016-04-12 23:06 - 2016-04-12 23:06 - 0023040 _____ () C:\Users\Darryl\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-02-28 18:07 - 2016-02-28 18:07 - 0003389 _____ () C:\Users\Darryl\AppData\Local\recently-used.xbel
2015-08-03 20:30 - 2015-08-03 20:30 - 0267353 _____ () C:\ProgramData\1438597611.bdinstall.bin
2011-01-09 14:36 - 2011-03-05 07:50 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2012-12-24 16:16 - 2012-12-24 16:16 - 0000120 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-07-14 11:30
==================== End of FRST.txt