OTL:
OTL logfile created on: 04-Sep-16 5:29:01 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\TDW\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18426)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-MMM-yy
3.49 Gb Total Physical Memory | 1.73 Gb Available Physical Memory | 49.52% Memory free
6.98 Gb Paging File | 4.62 Gb Available in Paging File | 66.24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 358.48 Gb Free Space | 76.98% Space Free | Partition Type: NTFS
Drive E: | 931.48 Gb Total Space | 711.67 Gb Free Space | 76.40% Space Free | Partition Type: NTFS
Computer Name: USER-PC | User Name: TDW | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2016-09-04 16:43:27 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\TDW\Downloads\OTL.exe
PRC - [2016-08-25 08:49:25 | 004,602,872 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.66\deploy\LoLPatcher.exe
PRC - [2016-08-25 08:49:12 | 002,409,464 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.26\deploy\LoLLauncher.exe
PRC - [2016-08-03 13:33:38 | 000,339,968 | ---- | M] (Popcorn Time) -- C:\Program Files\Popcorn Time\Updater.exe
PRC - [2016-06-25 01:45:12 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2016-05-25 10:31:20 | 001,687,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2016-05-25 10:30:36 | 001,364,096 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2016-05-21 17:14:49 | 000,074,752 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\LolClient.exe
PRC - [2016-05-21 16:31:35 | 001,294,336 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
PRC - [2016-04-09 08:44:07 | 002,973,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2015-06-18 08:39:50 | 001,133,880 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
PRC - [2012-11-23 05:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2011-10-26 05:01:18 | 000,417,792 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2011-10-26 05:00:46 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2011-03-22 11:37:16 | 000,497,480 | ---- | M] (Splashtop Inc.) -- C:\Program Files\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe
PRC - [2010-11-15 14:21:54 | 000,477,000 | ---- | M] (Splashtop Inc.) -- C:\Program Files\Splashtop\Splashtop Connect\BackService.exe
PRC - [2010-10-06 08:04:12 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010-10-06 08:04:08 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
========== Modules (No Company Name) ==========
MOD - [2016-08-25 08:49:25 | 004,602,872 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.66\deploy\LoLPatcher.exe
MOD - [2016-08-25 08:49:25 | 000,449,528 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.66\deploy\RiotLauncher.dll
MOD - [2016-08-25 08:49:12 | 002,409,464 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.1.26\deploy\LoLLauncher.exe
MOD - [2016-05-21 17:14:49 | 000,074,752 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\LolClient.exe
MOD - [2016-05-21 16:36:15 | 004,887,216 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\Adobe AIR\Versions\1.0\Resources\WebKit.dll
MOD - [2016-05-21 16:34:39 | 019,397,808 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\Adobe AIR\Versions\1.0\Resources\NPSWF32.dll
MOD - [2016-05-21 16:31:35 | 001,294,336 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
MOD - [2013-09-05 01:14:10 | 004,300,456 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2012-02-17 20:55:35 | 000,166,912 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Program Files\Splashtop\Splashtop Connect Firefox Software Updater\WCUService.exe -- (WCUService_STC_FF)
SRV - [2016-08-23 22:33:10 | 001,465,120 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2016-08-03 13:33:38 | 000,339,968 | ---- | M] (Popcorn Time) [Auto | Running] -- C:\Program Files\Popcorn Time\Updater.exe -- (Update service)
SRV - [2016-08-02 08:41:49 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2016-07-14 19:45:17 | 000,270,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2016-06-25 01:45:12 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2016-05-25 10:31:20 | 001,687,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2016-05-25 10:30:36 | 001,364,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2016-05-23 15:17:32 | 000,324,224 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2016-02-24 10:15:00 | 004,362,656 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2015-07-22 20:53:34 | 000,937,984 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\diagtrack.dll -- (DiagTrack)
SRV - [2015-06-18 08:39:50 | 001,133,880 | ---- | M] (Malwarebytes Corporation) [Auto | Start_Pending] -- C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013-12-19 01:41:02 | 030,814,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2013-05-27 07:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012-12-04 06:58:44 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011-10-26 05:00:46 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011-03-22 11:37:16 | 000,497,480 | ---- | M] (Splashtop Inc.) [Auto | Running] -- C:\Program Files\Splashtop\Splashtop Connect IE Software Updater\WCUService.exe -- (WCUService_STC_IE)
SRV - [2010-11-15 14:21:54 | 000,477,000 | ---- | M] (Splashtop Inc.) [Auto | Running] -- C:\Program Files\Splashtop\Splashtop Connect\BackService.exe -- (SCBackService)
SRV - [2010-10-06 08:04:12 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010-10-06 08:04:08 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2009-07-14 04:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009-07-14 04:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2005-09-23 08:01:16 | 002,799,808 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon80)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | Auto | Stopped] -- C:\PROGRA~1\YTDOWN~1\sbmntr.sys -- (sbmntr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\mcdbus.sys -- (mcdbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\massfilter.sys -- (massfilter)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\EagleXNt.sys -- (EagleXNt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgandnetndis.sys -- (andnetndis)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgandnetmodem.sys -- (ANDNetModem)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\lgandnetdiag.sys -- (AndNetDiag)
DRV - [2015-09-21 19:05:06 | 000,094,936 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamchameleon.sys -- (mbamchameleon)
DRV - [2015-06-18 08:41:54 | 000,051,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mwac.sys -- (MBAMWebAccessControl)
DRV - [2015-06-18 08:41:36 | 000,023,256 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2015-06-11 20:15:04 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2014-05-26 22:38:43 | 000,126,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ESETOlmarikOlmascoCleaner.sys -- (ESETOlmarikOlmascoCleaner)
DRV - [2013-03-22 01:01:10 | 000,229,208 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\VMM.sys -- (vmm)
DRV - [2012-12-05 03:20:05 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2011-10-26 06:03:48 | 008,853,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2011-10-26 04:21:36 | 000,264,192 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2011-05-25 14:19:00 | 000,061,824 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\EtronXHCI.sys -- (EtronXHCI)
DRV - [2011-05-25 14:19:00 | 000,041,600 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\EtronHub3.sys -- (EtronHub3)
DRV - [2010-11-21 00:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010-11-21 00:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010-11-21 00:29:03 | 000,112,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - [2010-11-21 00:29:03 | 000,077,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV - [2010-11-21 00:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010-11-21 00:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010-11-21 00:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010-11-21 00:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010-11-21 00:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010-11-21 00:29:03 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\terminpt.sys -- (terminpt)
DRV - [2010-11-21 00:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010-11-21 00:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010-09-21 20:59:02 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2009-07-14 02:53:36 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\loop.sys -- (msloop)
DRV - [2009-03-19 03:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008-05-07 03:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2007-01-29 07:20:34 | 000,059,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VMNetSrv.sys -- (VPCNetS2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = DB AB 16 10 77 04 D2 01 [binary data]
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = Reg Error: Value error.
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\..\URLSearchHook: {0F3DC9E0-C459-4a40-BCF8-747BD9322E10} - C:\Program Files\Splashtop\Splashtop Connect IE\AddressBarSearch.dll (Splashtop Inc.)
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\..\SearchScopes,DefaultScope = {70839579-320E-4763-A420-8468514E4F69}
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\..\SearchScopes\{271B4DEB-E9E4-4842-86EF-B5255AAFB2F5}: "URL" =
http://search.yahoo.com/search?p={searc ... ype=IEBDSV
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\..\SearchScopes\{5AC76C24-D9F8-4e70-A2F7-A4C133AA872C}: "URL" =
http://www.google.com/cse?cx=partner-pu ... earchTerms}
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\..\SearchScopes\{70839579-320E-4763-A420-8468514E4F69}: "URL" =
http://www.bing.com/search?q={searchTer ... ORM=IESR02
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.31.2: C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.31.2: C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\TDW\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
[2016-08-21 11:21:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\TDW\AppData\Roaming\mozilla\Firefox\Profiles\aZyQ7RhB.default\extensions
[2016-08-21 11:22:01 | 000,000,000 | ---D | M] (Avira Browser Safety) -- C:\Users\TDW\AppData\Roaming\mozilla\Firefox\Profiles\aZyQ7RhB.default\extensions\
abs@avira.com
========== Chrome ==========
CHR - Extension: No name found = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.1.2.0_0\
O1 HOSTS File: ([2009-06-11 00:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (surf and keeP) - {0451830B-94C5-4CF4-CFCA-2F06DF13BF18} - C:\Program Files\surf and keeP\MhFaMvjkgH.dll File not found
O2 - BHO: (Splashtop Connect VisualBookmark) - {0E5680D1-BF44-4929-94AF-FD30D784AD1D} - C:\Program Files\Splashtop\Splashtop Connect IE\STC.dll (Splashtop Inc.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (surf and keep) - {C635E43A-42F4-7B54-C7A8-124A2ECE0D07} - C:\Program Files\surf and keep\FiD5.dll File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [NeroFilterCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [STCAgent] C:\Program Files\Splashtop\Splashtop Connect IE\STCAgent.exe (Splashtop Inc.)
O4 - HKLM..\Run: [ZyngaGamesAgent] "C:\Program Files\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe" File not found
O4 - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1390296456-3514786238-1037386279-1003\..Trusted Domains: tlush.gov.il ([]https in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F83BC11-E58F-45EB-9001-D6099356579E}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O27 - HKLM IFEO\bitguard.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bprotect.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bpsvc.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserdefender.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserprotect.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsersafeguard.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\dprotectsvc.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\jumpflip: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\protectedsearch.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchinstaller.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotection.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotector.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchsettings.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchsettings64.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\snapdo.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst32.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst64.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\umbrella.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\utiljumpflip.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\volaro: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\vonteera: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\websteroids.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\websteroidsservice.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012-04-06 05:29:53 | 000,000,020 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (aswBoot.exe /M:3de0a5a6 /dir:"C:\Program Files\AVAST Software\Avast")
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2016-09-04 12:21:00 | 000,000,000 | ---D | C] -- C:\Program Files\trend micro
[2016-09-04 12:20:59 | 000,000,000 | ---D | C] -- C:\rsit
[2016-09-03 18:41:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2016-09-03 18:29:29 | 000,000,000 | ---D | C] -- C:\Nexon
[2016-08-26 22:19:30 | 000,000,000 | ---D | C] -- C:\Users\TDW\AppData\Roaming\uTorrent
[2016-08-25 10:34:38 | 000,000,000 | ---D | C] -- C:\Users\TDW\AppData\Local\PopcornTimeDesktop
[2016-08-25 10:34:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Popcorn Time
[2016-08-25 10:34:07 | 000,000,000 | ---D | C] -- C:\Program Files\Popcorn Time
[2016-08-21 11:33:25 | 000,000,000 | ---D | C] -- C:\Users\TDW\AppData\Local\AviraSpeedup
[2016-08-21 11:31:45 | 000,000,000 | ---D | C] -- C:\Users\TDW\AppData\Local\Avira
[2016-08-21 11:21:59 | 000,000,000 | ---D | C] -- C:\Users\TDW\AppData\Roaming\Mozilla
[2016-08-21 11:16:37 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2016-08-17 06:50:49 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2016-08-15 10:44:51 | 000,000,000 | ---D | C] -- C:\Users\TDW\AppData\Local\Diagnostics
[2016-08-10 12:06:30 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adtschema.dll
[2016-08-10 12:06:30 | 000,223,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2016-08-10 12:06:30 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msaudite.dll
[2016-08-10 12:06:30 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rpchttp.dll
[2016-08-10 12:06:30 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msobjs.dll
[2016-08-10 12:06:30 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\auditpol.exe
[2016-08-10 12:06:30 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2016-08-10 12:06:21 | 002,399,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2016-08-10 12:06:18 | 000,689,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2016-08-10 12:06:18 | 000,667,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MsSpellCheckingFacility.exe
[2016-08-10 12:06:18 | 000,346,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2016-08-10 12:06:18 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollector.exe
[2016-08-10 12:06:18 | 000,091,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inseng.dll
[2016-08-10 12:06:18 | 000,060,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\JavaScriptCollectionAgent.dll
[2016-08-10 12:06:18 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwproxystub.dll
[2016-08-10 12:06:18 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2016-08-10 12:06:17 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2016-08-10 12:06:17 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2016-08-10 12:06:17 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2016-08-10 12:06:17 | 000,620,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9diag.dll
[2016-08-10 12:06:17 | 000,416,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtmsft.dll
[2016-08-10 12:06:17 | 000,115,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2016-08-10 12:06:17 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2016-08-10 12:06:16 | 002,055,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2016-08-10 12:06:15 | 000,168,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msrating.dll
[2016-08-10 12:06:15 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2016-08-10 12:06:15 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieetwcollectorres.dll
[2016-08-10 12:06:14 | 000,279,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dxtrans.dll
[2016-08-10 12:06:13 | 000,476,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2016-08-10 12:06:11 | 000,341,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2016-08-10 12:06:10 | 001,155,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtmlmedia.dll
[2016-08-10 12:06:10 | 000,064,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MshtmlDac.dll
[2016-08-10 12:06:06 | 004,608,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
========== Files - Modified Within 30 Days ==========
[2016-09-04 17:29:46 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2016-09-04 17:24:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA1cf8b17df2dec8d.job
[2016-09-04 17:20:02 | 000,000,510 | ---- | M] () -- C:\Windows\tasks\G2MUpdateTask-S-1-5-21-1390296456-3514786238-1037386279-1003.job
[2016-09-04 16:45:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2016-09-04 16:43:00 | 000,000,512 | ---- | M] () -- C:\Windows\tasks\G2MUpdateTask-S-1-5-21-1390296456-3514786238-1037386279-1000.job
[2016-09-04 16:42:01 | 000,000,606 | ---- | M] () -- C:\Windows\tasks\G2MUploadTask-S-1-5-21-1390296456-3514786238-1037386279-1003.job
[2016-09-04 16:02:34 | 000,854,923 | ---- | M] () -- C:\Users\TDW\Desktop\Capture.png
[2016-09-04 15:47:51 | 000,029,376 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016-09-04 15:47:51 | 000,029,376 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016-09-04 15:45:00 | 000,000,608 | ---- | M] () -- C:\Windows\tasks\G2MUploadTask-S-1-5-21-1390296456-3514786238-1037386279-1000.job
[2016-09-04 10:52:46 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016-09-04 10:52:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016-09-04 10:52:13 | 2811,682,816 | -HS- | M] () -- C:\hiberfil.sys
[2016-09-03 18:41:56 | 000,000,204 | ---- | M] () -- C:\Users\Public\Desktop\MapleStory.url
[2016-08-25 10:34:20 | 000,001,941 | ---- | M] () -- C:\Users\Public\Desktop\Popcorn Time.lnk
[2016-08-21 11:29:58 | 000,441,032 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2016-08-09 12:26:51 | 000,002,123 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
========== Files Created - No Company Name ==========
[2016-09-04 17:27:28 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2016-09-04 15:46:15 | 000,854,923 | ---- | C] () -- C:\Users\TDW\Desktop\Capture.png
[2016-09-03 18:41:56 | 000,000,204 | ---- | C] () -- C:\Users\Public\Desktop\MapleStory.url
[2016-08-25 10:34:20 | 000,001,941 | ---- | C] () -- C:\Users\Public\Desktop\Popcorn Time.lnk
[2016-08-16 10:53:00 | 000,441,032 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2016-06-11 15:53:24 | 000,000,016 | ---- | C] () -- C:\ProgramData\mntemp
[2015-12-21 20:58:15 | 000,007,594 | ---- | C] () -- C:\Users\TDW\AppData\Local\Resmon.ResmonCfg
[2015-11-08 21:07:49 | 000,000,000 | ---- | C] () -- C:\Windows\MERP.INI
[2015-11-08 20:46:24 | 000,000,000 | ---- | C] () -- C:\Windows\APPWIZ32.INI
[2015-08-09 14:38:38 | 000,001,108 | RHS- | C] () -- C:\Users\TDW\ntuser.pol
========== ZeroAccess Check ==========
[2009-07-14 07:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016-04-09 09:54:53 | 012,881,408 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010-11-21 00:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009-07-14 04:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012-12-07 05:37:39 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Splashtop
[2015-08-16 20:07:20 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\.minecraft
[2015-10-19 22:35:47 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Axonstall
[2015-11-24 23:53:12 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\DassaultSystemes
[2015-11-25 01:39:49 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\EDrawings
[2015-12-03 18:36:41 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\fizzy
[2015-08-09 20:21:50 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\java
[2015-09-30 07:36:58 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\LolClient
[2016-05-21 16:31:04 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Riot Games
[2015-08-09 14:38:56 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Splashtop
[2016-05-31 15:04:28 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\steam.transformice.com
[2016-09-03 06:04:17 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\uTorrent
[2015-08-06 19:54:52 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\.minecraft
[2015-07-11 21:40:26 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\ESET
[2013-01-01 02:03:45 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\fizzy
[2015-08-06 19:52:40 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\java
[2015-03-05 11:17:46 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\LibreOffice
[2013-06-17 11:02:12 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\LolClient
[2015-04-13 16:09:59 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\MiniGet
[2014-05-21 16:30:40 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\OpenOffice
[2015-04-13 16:08:10 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Opera Software
[2013-02-02 10:53:12 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Origin
[2015-06-10 18:17:39 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\PerformerSoft
[2014-08-06 15:02:20 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Riot Games
[2013-10-09 16:41:50 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\rockbox.org
[2014-12-10 21:54:09 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\SanDisk
[2012-12-04 06:21:21 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Splashtop
[2015-02-28 21:50:49 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Transformice
[2015-08-08 22:16:46 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\uTorrent
[2015-01-19 17:37:33 | 000,000,000 | ---D | M] -- C:\Users\user\AppData\Roaming\Wargaming.net
========== Purity Check ==========
========== Custom Scans ==========
< >
[2009-07-14 07:53:46 | 000,032,652 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009-07-14 07:53:47 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2013-01-14 00:36:09 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2013-04-19 19:39:18 | 000,000,882 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2014-06-18 20:08:06 | 000,000,886 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf8b17df2dec8d.job
[2015-06-03 20:23:53 | 000,000,512 | ---- | C] () -- C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1390296456-3514786238-1037386279-1000.job
[2015-06-15 16:33:51 | 000,000,608 | ---- | C] () -- C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1390296456-3514786238-1037386279-1000.job
[2016-05-15 21:57:34 | 000,000,510 | ---- | C] () -- C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1390296456-3514786238-1037386279-1003.job
[2016-05-15 21:57:35 | 000,000,606 | ---- | C] () -- C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1390296456-3514786238-1037386279-1003.job
< >
< MD5 for: ATAPI.SYS >
[2009-07-14 04:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009-07-14 04:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_a5025d31bee4647c\atapi.sys
[2009-07-14 04:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009-07-14 04:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys
[2009-07-14 04:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.18231_none_df26d4d57fdef5b0\atapi.sys
[2009-07-14 04:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.22414_none_dfc9143c98e9a6c4\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2010-11-21 00:29:06 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\System32\autochk.exe
[2010-11-21 00:29:06 | 000,668,160 | ---- | M] (Microsoft Corporation) MD5=F88A52EB62019D6A62FDD9E08034DBD8 -- C:\Windows\winsxs\x86_microsoft-windows-autochk_31bf3856ad364e35_6.1.7601.17514_none_e3fb573520033bfa\autochk.exe
< MD5 for: CDROM.SYS >
[2010-11-21 00:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\System32\drivers\cdrom.sys
[2010-11-21 00:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.sys
[2010-11-21 00:29:03 | 000,108,544 | ---- | M] (Microsoft Corporation) MD5=BE167ED0FDB9C1FA1133953C18D5A6C9 -- C:\Windows\winsxs\x86_cdrom.inf_31bf3856ad364e35_6.1.7601.17514_none_61b0c5ce02098355\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2016-01-22 08:12:59 | 002,973,184 | ---- | M] (Microsoft Corporation) MD5=2A156D5EBF221EF2A6AE7CE452324DAC -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.19135_none_53a73c47d80e17a9\explorer.exe
[2016-04-09 08:44:07 | 002,973,184 | ---- | M] (Microsoft Corporation) MD5=3DA48EA028AD771C5B71727F0C3984E9 -- C:\Windows\explorer.exe
[2016-04-09 08:44:07 | 002,973,184 | ---- | M] (Microsoft Corporation) MD5=3DA48EA028AD771C5B71727F0C3984E9 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.23418_none_54497d94f118c5e4\explorer.exe
[2010-11-21 00:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2016-01-22 09:07:00 | 002,973,696 | ---- | M] (Microsoft Corporation) MD5=CEA6C2000AEC6CAF3CD6F3F73848E40A -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.23338_none_5433dbd6f129009f\explorer.exe
< MD5 for: HAL.DLL >
[2010-11-21 00:29:19 | 000,194,432 | ---- | M] (Microsoft Corporation) MD5=1BF0D4727FDB437D513CFF8A9359C050 -- C:\Windows\System32\hal.dll
[2010-11-21 00:29:19 | 000,194,432 | ---- | M] (Microsoft Corporation) MD5=1BF0D4727FDB437D513CFF8A9359C050 -- C:\Windows\winsxs\x86_microsoft-windows-hal_31bf3856ad364e35_6.1.7601.17514_none_ad305c8fb7ec5060\hal.dll
< MD5 for: SCECLI.DLL >
[2010-11-21 00:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\System32\scecli.dll
[2010-11-21 00:29:07 | 000,175,616 | ---- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 -- C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_3a154c47375d881d\scecli.dll
< MD5 for: SERVICES.EXE >
[2015-04-13 06:19:24 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=0780A42DBD7D9969F9BF4A19AA4285B5 -- C:\Windows\System32\services.exe
[2015-04-13 06:19:24 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=0780A42DBD7D9969F9BF4A19AA4285B5 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7601.18829_none_d1614ac32b8ec5cf\services.exe
[2009-07-14 04:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe
[2015-04-11 06:53:55 | 000,259,072 | ---- | M] (Microsoft Corporation) MD5=97981140500E86E5BBAD7B76BA890146 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7601.23033_none_d1d9ee0844ba1cc2\services.exe
< MD5 for: SVCHOST.EXE >
[2015-09-21 19:04:23 | 000,893,752 | ---- | M] (MalwareBytes) MD5=0692C8163852AB5674E2EB3B36131EF3 -- C:\Users\TDW\Downloads\Chameleon\Windows\svchost.exe
[2009-07-14 04:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\System32\svchost.exe
[2009-07-14 04:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
< MD5 for: TCPIP.SYS >
[2010-11-21 00:29:20 | 001,290,112 | ---- | M] (Microsoft Corporation) MD5=37E8FA3779668837CA9E2C36D2415949 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17514_none_b5257c3dc4a85a01\tcpip.sys
[2014-04-05 05:25:01 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=5579DD18546999F5D0EC39D018726C6B -- C:\Windows\System32\drivers\tcpip.sys
[2014-04-05 05:25:01 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=5579DD18546999F5D0EC39D018726C6B -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18438_none_b513c4dfc4b513b9\tcpip.sys
[2013-09-07 05:06:48 | 001,309,120 | ---- | M] (Microsoft Corporation) MD5=6C4F3D92764FFA22D28061A4D9235446 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22444_none_b58e8eb0ddde6cf1\tcpip.sys
[2013-09-08 05:07:12 | 001,294,272 | ---- | M] (Microsoft Corporation) MD5=CA59F7C570AF70BC174F477CFE2D9EE3 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.18254_none_b4fa2013c4c8ebf1\tcpip.sys
[2012-10-03 19:44:01 | 001,308,040 | ---- | M] (Microsoft Corporation) MD5=D490DD0A91B4EAC3B4EE08D11EE37C31 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22124_none_b5a428d6ddce3d9a\tcpip.sys
[2013-11-26 14:07:37 | 001,309,632 | ---- | M] (Microsoft Corporation) MD5=DC08335B30D83FB61E9EFE6FDD09D40D -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22525_none_b5a530b8ddcd4b8d\tcpip.sys
[2012-10-03 19:58:30 | 001,293,680 | ---- | M] (Microsoft Corporation) MD5=E23A56F843E2AEBBB209D0ACCA73C640 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.17964_none_b4ef7439c4d0da52\tcpip.sys
[2014-04-05 05:16:21 | 001,310,144 | ---- | M] (Microsoft Corporation) MD5=EA47AB18E289333AB94397D77CA6E3A1 -- C:\Windows\winsxs\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.1.7601.22648_none_b59293a4dddacc9b\tcpip.sys
< MD5 for: USERINIT.EXE >
[2010-11-21 00:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010-11-21 00:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
< MD5 for: WINLOGON.EXE >
[2015-09-21 19:04:24 | 000,893,752 | ---- | M] (MalwareBytes) MD5=0692C8163852AB5674E2EB3B36131EF3 -- C:\Users\TDW\Downloads\Chameleon\Windows\winlogon.exe
[2014-07-16 05:56:14 | 000,304,640 | ---- | M] (Microsoft Corporation) MD5=4F37B93C14AEE313BEC52A23AFB15C2E -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22750_none_7224b2134c7555fa\winlogon.exe
[2014-07-17 04:39:27 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=52449FD429D6053B78AE564DEF303870 -- C:\Windows\System32\winlogon.exe
[2014-07-17 04:39:27 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=52449FD429D6053B78AE564DEF303870 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18540_none_71a5e34e334f9d18\winlogon.exe
[2010-11-21 00:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2014-03-04 12:17:02 | 000,304,128 | ---- | M] (Microsoft Corporation) MD5=998507B046BA314CE8245364C686FA67 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_71da23b23327143c\winlogon.exe
[2014-03-04 13:39:02 | 000,304,640 | ---- | M] (Microsoft Corporation) MD5=D53972F87D850CD2EB4B29B60CAFDD77 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_7255f1994c4f8119\winlogon.exe
< >
< %systemroot%*.* /U /s >
[10 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[51 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\61bfe288eb8e4176873cdcd21610e16d\*.tmp files -> C:\Windows\SoftwareDistribution\Download\61bfe288eb8e4176873cdcd21610e16d\*.tmp -> ]
[1 C:\Windows\SoftwareDistribution\Download\a92f8878ea38cac4505fcefd787bd88e\*.tmp files -> C:\Windows\SoftwareDistribution\Download\a92f8878ea38cac4505fcefd787bd88e\*.tmp -> ]
[2 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
[1 C:\Windows\Temp\is-RDOBJ.tmp\*.tmp files -> C:\Windows\Temp\is-RDOBJ.tmp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2015-08-16 20:07:20 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\.minecraft
[2015-08-12 14:14:47 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Adobe
[2015-10-19 22:35:47 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Axonstall
[2015-11-24 23:53:12 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\DassaultSystemes
[2015-08-17 10:17:38 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\dvdcss
[2015-11-25 01:39:49 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\EDrawings
[2015-12-03 18:36:41 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\fizzy
[2015-08-09 14:38:44 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Identities
[2015-08-09 20:21:50 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\java
[2015-09-30 07:36:58 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\LolClient
[2013-01-04 05:26:01 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Macromedia
[2010-11-21 03:46:50 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Media Center Programs
[2016-08-09 19:44:13 | 000,000,000 | --SD | M] -- C:\Users\TDW\AppData\Roaming\Microsoft
[2016-08-21 11:21:59 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Mozilla
[2016-05-21 16:31:04 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Riot Games
[2016-09-03 18:03:00 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Skype
[2015-11-30 23:15:29 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\SOLIDWORKS
[2015-11-30 23:15:29 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\SolidWorks 2014
[2015-08-09 14:38:56 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\Splashtop
[2016-05-31 15:04:28 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\steam.transformice.com
[2016-09-03 06:04:17 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\uTorrent
[2016-09-03 05:07:36 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\vlc
[2015-09-29 17:53:34 | 000,000,000 | ---D | M] -- C:\Users\TDW\AppData\Roaming\WinRAR
< %APPDATA%\*.exe /s >
[2015-06-18 11:40:22 | 000,015,360 | ---- | M] () -- C:\Users\TDW\AppData\Roaming\Axonstall\AxProtector.exe
[2012-09-06 02:04:02 | 000,445,352 | ---- | M] (wyDay) -- C:\Users\TDW\AppData\Roaming\Axonstall\wyUpdate.exe
[2015-02-28 21:51:52 | 000,054,432 | ---- | M] (Adobe Systems Inc.) -- C:\Users\TDW\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
[2016-08-17 00:10:16 | 002,370,560 | ---- | M] (BitTorrent Inc.) -- C:\Users\TDW\AppData\Roaming\uTorrent\uTorrent.exe
[2016-08-17 00:10:16 | 002,370,560 | ---- | M] (BitTorrent Inc.) -- C:\Users\TDW\AppData\Roaming\uTorrent\updates\3.4.8_42449.exe
[2016-08-26 22:21:54 | 000,387,072 | ---- | M] (BitTorrent Inc.) -- C:\Users\TDW\AppData\Roaming\uTorrent\updates\3.4.8_42449\utorrentie.exe
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job >
[2016-09-04 16:45:00 | 000,000,830 | ---- | M] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job
[2016-09-04 17:43:00 | 000,000,512 | ---- | M] () -- C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1390296456-3514786238-1037386279-1000.job
[2016-09-04 17:20:02 | 000,000,510 | ---- | M] () -- C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1390296456-3514786238-1037386279-1003.job
[2016-09-04 15:45:00 | 000,000,608 | ---- | M] () -- C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1390296456-3514786238-1037386279-1000.job
[2016-09-04 16:42:01 | 000,000,606 | ---- | M] () -- C:\Windows\Tasks\G2MUploadTask-S-1-5-21-1390296456-3514786238-1037386279-1003.job
[2016-09-04 10:52:46 | 000,000,882 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2016-09-04 17:24:00 | 000,000,886 | ---- | M] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA1cf8b17df2dec8d.job
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\system32\drivers\*.sys /3 >
< %systemroot%\system32\*.* /3 >
[2016-09-04 15:47:51 | 000,029,376 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2016-09-04 15:47:51 | 000,029,376 | -H-- | M] () -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2016-09-04 10:54:36 | 000,000,018 | ---- | M] () -- C:\Windows\system32\log.txt
< %SYSTEMDRIVE%\*.exe >
< >
< HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /s >
"Steam" = "C:\Program Files\Steam\steam.exe" -silent -- [2016-08-23 22:33:10 | 002,857,248 | ---- | M] (Valve Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Speedup DelayLoad]
< >
< %PROGRAMFILES%\Mozilla Firefox\firefox.exe /md5 >
< %PROGRAMFILES%\Internet Explorer\iexplore.exe /md5 >
[2016-08-02 17:08:56 | 000,815,312 | ---- | M] (Microsoft Corporation) MD5=C5481C540C36793450318BCA4AD219DC -- C:\Program Files\Internet Explorer\iexplore.exe
< %PROGRAMFILES%\Opera\opera.exe /md5 >
< %PROGRAMFILES%\Google\Chrome\Application\chrome.exe /md5 >
[2016-08-03 03:20:56 | 000,961,352 | ---- | M] (Google Inc.) MD5=D6393757CDE040A51306221842EA5C0A -- C:\Program Files\Google\Chrome\Application\chrome.exe
< >
< %SystemDrive%\PhysicalMBR.bin /md5 >
[2016-09-04 17:29:46 | 000,000,512 | ---- | M] () MD5=1D7A138FAE50D8FB8D691F67E343D1A2 -- C:\PhysicalMBR.bin
< >
< *crack* /s >
< *keygen* /s >
< *loader* /s >
[2009-05-23 13:38:52 | 000,061,952 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7Debug\coloader80.dll
[2009-05-23 08:27:34 | 000,004,608 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VS7Debug\coloader80.tlb
[2014-09-03 01:27:24 | 000,268,432 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll
[2014-09-03 01:27:24 | 000,019,096 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll
[2013-03-09 04:48:16 | 000,017,544 | ---- | M] () -- \Program Files\Common Files\microsoft shared\VSTO\10.0\1037\VSTOLoaderUI.dll
[2015-03-06 13:25:14 | 004,249,592 | ---- | M] () -- \Program Files\Common Files\SOLIDWORKS Installation Manager\23.0\sldimdownloader.exe
[2014-12-10 03:17:20 | 000,001,701 | ---- | M] () -- \Program Files\Steam\friends\broadcastuploaderrornotification.res
[2013-07-20 05:18:04 | 000,007,825 | ---- | M] () -- \Program Files\Steam\remoteui\static\libs\images\ajax-loader.gif
[2013-06-02 23:49:44 | 000,001,180 | ---- | M] () -- \ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NCdownloader.lnk
[2016-05-21 16:36:15 | 000,000,404 | ---- | M] () -- \Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\assets\htmlTemplates\events\bwRewards\img\loader-squares.gif
[2016-05-21 16:36:15 | 000,050,167 | ---- | M] () -- \Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\assets\htmlTemplates\events\bwRewards\img\loader.gif
[2016-05-21 17:12:43 | 000,000,404 | ---- | M] () -- \Riot Games\League of Legends\RADS\projects\lol_air_client\releases\0.0.1.214\deploy\assets\storeImages\layout\small_loader.gif
[2013-06-02 23:49:44 | 000,001,180 | ---- | M] () -- \Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\NCdownloader.lnk
[2016-09-02 21:28:00 | 000,001,893 | ---- | M] () -- \Users\TDW\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6U1SPJ86\AdLoader-v2[1].htm
[2016-09-02 21:28:00 | 000,029,271 | ---- | M] () -- \Users\TDW\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I88J3K68\AdLoader-v2-85ff019d29b074e4baace8aeb202ecf1.min[1].js
[2016-09-03 05:11:16 | 000,067,768 | ---- | M] () -- \Users\TDW\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ECAACGXZ\loader[1].js
[2015-11-24 22:59:04 | 000,001,100 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\2014 SP2.0\Other Logs\IMDownloaderVersion.xml
[2015-11-24 23:40:44 | 002,462,436 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\2014 SP2.0\Other Logs\sldIMDownloaderLog_00001.txt
[2015-11-24 21:04:17 | 000,001,100 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\2015 SP2.1\Other Logs\IMDownloaderVersion.xml
[2015-11-24 22:25:29 | 008,197,446 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\2015 SP2.1\Other Logs\sldIMDownloaderLog_00001.txt
[2015-11-24 21:04:19 | 000,001,612 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\Misc Logs\sldIMDownloaderLog_00001.txt
[2015-11-24 21:05:51 | 000,002,444 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\Misc Logs\sldIMDownloaderLog_00002.txt
[2015-11-24 22:59:07 | 000,001,612 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\Misc Logs\sldIMDownloaderLog_00003.txt
[2015-11-24 23:10:06 | 000,002,446 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\Misc Logs\sldIMDownloaderLog_00004.txt
[2016-03-22 22:58:45 | 000,001,600 | ---- | M] () -- \Users\TDW\AppData\Roaming\SOLIDWORKS\Installation Logs\Misc Logs\sldIMDownloaderLog_00005.txt
[2015-10-22 20:03:47 | 000,003,297 | ---- | M] () -- \Users\TDW\eclipse\java-mars\eclipse\configuration\org.eclipse.osgi\238\0\.cp\org\eclipse\m2e\core\ui\internal\wizards\MavenProjectWizardArchetypeParametersPage$RequiredPropertiesLoader.class
[2015-06-05 20:08:42 | 000,072,638 | ---- | M] () -- \Users\user\AppData\Local\Skype\Apps\login\images\loader.gif
[2015-06-05 20:08:42 | 000,003,032 | ---- | M] () -- \Users\user\AppData\Local\Skype\Apps\login\images\loader.png
[2015-06-05 20:08:42 | 000,006,012 | ---- | M] () -- \Users\user\AppData\Local\Skype\Apps\login\images\normal\loader_15fps.gif
[2015-06-05 20:08:42 | 000,021,956 | ---- | M] () -- \Users\user\AppData\Local\Skype\Apps\login\images\normal\loader_30fps.gif
[2015-06-05 20:08:42 | 000,009,772 | ---- | M] () -- \Users\user\AppData\Local\Skype\Apps\login\images\retina\
loader@2x.png
[2012-11-19 23:13:34 | 000,000,847 | ---- | M] () -- \Users\user\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ac\img\ajax-loader.gif
[2012-11-19 23:13:34 | 000,001,135 | ---- | M] () -- \Users\user\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ac\img\loader-icon.png
[2012-11-19 23:13:34 | 000,003,208 | ---- | M] () -- \Users\user\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\ui\gf\img\loader.gif
[2012-11-19 23:13:34 | 000,001,849 | ---- | M] () -- \Users\user\AppData\Roaming\Mozilla\Firefox\extensions\{b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14}\chrome\CT3225826\content\tb\al\wa\TWITTER\resources\ajax-loader.gif
[2013-04-11 18:54:38 | 000,197,614 | ---- | M] () -- \Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
ftdownloader3@ftdownloader.com.xpi
[2012-12-13 23:29:00 | 000,199,445 | ---- | M] () -- \Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\
movie2kdownloader@movie2kdownloader.com.xpi
[2013-03-09 09:17:04 | 000,019,080 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
[2010-03-25 07:12:34 | 000,018,264 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2013-03-09 09:17:04 | 000,268,440 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8
[2010-03-25 07:12:34 | 000,249,680 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109110000000000000000F01FEC\14.0.4763\VSTOLoader_dll_x86.3643236F_FC70_11D3_A536_0090278A1BB8.923C1899_09AE_418B_B39D_A7A9EB6A7951
[2009-10-23 00:15:32 | 000,016,712 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\00004109E600D0400000000000F01FEC\14.0.4763\FL_VSTOLoaderUI_dll_122707_122707_x86_heb.3643236F_FC70_11D3_A536_0090278A1BB8.5326715A_77CF_482B_8CA0_13476898242B
[2005-09-23 05:24:22 | 000,061,440 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\69AE184D3132C7A489EE17D0A18F48CA\8.0.50727\FL_coloader80_dll_128691_____X86.3643236F_FC70_11D3_A536_0090278A1BB8
[2005-09-23 00:23:44 | 000,004,608 | R--- | M] () -- \Windows\Installer\$PatchCache$\Managed\69AE184D3132C7A489EE17D0A18F48CA\8.0.50727\FL_coloader80_tlb_128927_____X86.3643236F_FC70_11D3_A536_0090278A1BB8
[2016-03-18 01:24:26 | 000,003,584 | -H-- | M] () -- \Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2009-07-14 04:15:12 | 000,038,400 | ---- | M] () -- \Windows\System32\dmloader.dll
[2015-04-13 16:10:05 | 000,003,566 | ---- | M] () -- \Windows\System32\Tasks\YTDownloader
[2015-04-13 16:10:00 | 000,003,888 | ---- | M] () -- \Windows\System32\Tasks\YTDownloaderUpd
[2009-07-14 07:54:01 | 000,003,532 | ---- | M] () -- \Windows\System32\Tasks\Microsoft\Windows\WindowsColorSystem\Calibration Loader
[2016-05-12 01:03:43 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23418_en-us_792d90885b602d98.manifest
[2016-05-12 01:03:43 | 000,033,000 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23418_en-us_792d90885b602d98_winload.exe.mui_3bc5b827
[2016-05-12 01:03:43 | 000,029,928 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23418_en-us_792d90885b602d98_winresume.exe.mui_ff8b5358
[2016-05-12 01:03:43 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23418_none_5dbb90b4e403376d.manifest
[2016-05-12 01:03:43 | 000,534,816 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23418_none_5dbb90b4e403376d_winload.exe_75835076
[2016-05-12 01:03:43 | 000,470,704 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23418_none_5dbb90b4e403376d_winresume.exe_85cd1215
[2009-07-14 05:17:38 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009-07-14 05:17:38 | 000,017,472 | ---- | M] () -- \Windows\winsxs\Backup\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23_spldr.sys_98bd87a0
[2015-05-13 22:06:00 | 000,000,612 | ---- | M] () -- \Windows\winsxs\FileMaps\programdata_microsoft_diagnosis_asimovuploader_0413bca0c3dfdda4.cdf-ms
[2010-11-21 03:37:59 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7600.16385_en-us_766f102945576be4.manifest
[2015-02-03 06:16:42 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.18741_en-us_787ca05342610b3b.manifest
[2015-01-16 09:23:55 | 000,002,777 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22923_en-us_791ddf705b6ca2f8.manifest
[2015-02-03 06:36:49 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.22948_en-us_790d410a5b78598d.manifest
[2015-04-27 22:04:39 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23040_en-us_790516dc5b7fc217.manifest
[2015-05-25 21:11:24 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23072_en-us_78e6a7ac5b964898.manifest
[2015-07-15 06:04:54 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23126_en-us_7920ba565b6a1f66.manifest
[2015-07-15 20:54:31 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23136_en-us_7915ea6a5b723b57.manifest
[2015-07-23 03:02:46 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23142_en-us_790719565b7df1ec.manifest
[2016-01-22 09:11:44 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23338_en-us_7917eeca5b706853.manifest
[2016-03-16 21:35:36 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23391_en-us_78d00d3c5ba75e98.manifest
[2016-03-18 01:34:51 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23392_en-us_78d10d865ba677ef.manifest
[2016-04-09 10:00:21 | 000,002,883 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..os-loader.resources_31bf3856ad364e35_6.1.7601.23418_en-us_792d90885b602d98.manifest
[2010-11-21 00:23:54 | 000,004,225 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.17514_none_5d2e241dcae8f953.manifest
[2015-02-03 06:32:58 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.18741_none_5d0aa07fcb041510.manifest
[2015-01-14 09:45:13 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22923_none_5dabdf9ce40faccd.manifest
[2015-02-03 06:54:42 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.22948_none_5d9b4136e41b6362.manifest
[2015-04-27 22:17:27 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23040_none_5d931708e422cbec.manifest
[2015-05-25 21:35:55 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23072_none_5d74a7d8e439526d.manifest
[2015-07-15 06:25:32 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23126_none_5daeba82e40d293b.manifest
[2015-07-15 21:16:39 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23136_none_5da3ea96e415452c.manifest
[2015-07-23 03:23:37 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23142_none_5d951982e420fbc1.manifest
[2016-01-22 09:39:54 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23338_none_5da5eef6e4137228.manifest
[2016-03-16 22:02:45 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23391_none_5d5e0d68e44a686d.manifest
[2016-03-18 01:51:44 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23392_none_5d5f0db2e44981c4.manifest
[2016-04-09 10:16:41 | 000,004,224 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-b..vironment-os-loader_31bf3856ad364e35_6.1.7601.23418_none_5dbb90b4e403376d.manifest
[2009-07-14 04:52:31 | 000,002,894 | ---- | M] () -- \Windows\winsxs\Manifests\x86_microsoft-windows-s..ive-blackbox-loader_31bf3856ad364e35_6.1.7600.16385_none_6b097e5cb26f7a23.manifest
[2009-07-14 04:15:12 | 000,038,400 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-audio-dmusic_31bf3856ad364e35_6.1.7600.16385_none_45ca7214f0f664cb\dmloader.dll
[2009-07-14 04:03:49 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7600.16385_none_0a884619dd2388ad\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-11-30 07:45:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18015_none_0cba39e5da114d7c\api-ms-win-core-libraryloader-l1-1-0.dll
[2013-08-02 04:48:15 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.18229_none_0cb36eedda15c917\api-ms-win-core-libraryloader-l1-1-0.dll
[2016-01-22 08:59:07 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.19135_none_0ca4852bda219c26\api-ms-win-core-libraryloader-l1-1-0.dll
[2012-11-30 07:46:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22177_none_0d04f7bcf35dc79a\api-ms-win-core-libraryloader-l1-1-0.dll
[2014-04-12 05:03:37 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.22653_none_0d169feaf3511c1f\api-ms-win-core-libraryloader-l1-1-0.dll
[2016-01-22 08:58:11 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23338_none_0d3124baf33c851c\api-ms-win-core-libraryloader-l1-1-0.dll
[2016-03-16 21:23:40 | 000,003,584 | ---- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23391_none_0ce9432cf3737b61\api-ms-win-core-libraryloader-l1-1-0.dll
[2016-03-18 01:24:26 | 000,003,584 | -H-- | M] () -- \Windows\winsxs\x86_microsoft-windows-minkernelapinamespace_31bf3856ad364e35_6.1.7601.23392_none_0cea4376f37294b8\api-ms-win-core-libraryloader-l1-1-0.dll
< Chat Conversation End >
========== Files - Unicode (All) ==========
[2016-08-01 13:11:23 | 000,032,064 | ---- | M] ()(C:\Users\TDW\Desktop\???? ??? ????? ???? ??? ??????? ?? ?????? ????? ???? ???? ??? ???? 058354242.docx) -- C:\Users\TDW\Desktop\מבחן בית בקורס חברת הים התיכוןן עפ תעודות גניזת קהיר מלכה כהן נהרי 058354242.docx
[2016-07-27 13:34:05 | 000,032,064 | ---- | C] ()(C:\Users\TDW\Desktop\???? ??? ????? ???? ??? ??????? ?? ?????? ????? ???? ???? ??? ???? 058354242.docx) -- C:\Users\TDW\Desktop\מבחן בית בקורס חברת הים התיכוןן עפ תעודות גניזת קהיר מלכה כהן נהרי 058354242.docx
[2016-07-12 15:58:23 | 000,033,415 | ---- | M] ()(C:\Users\TDW\Desktop\????? ????? ????, ???? ?????? - ???? ??? ???? ?.?. 058354242.docx) -- C:\Users\TDW\Desktop\עבודה בקורס גרוש, גלות וגאולה - מלכה כהן נהרי מ.ז. 058354242.docx
[2016-07-12 10:39:24 | 000,033,415 | ---- | C] ()(C:\Users\TDW\Desktop\????? ????? ????, ???? ?????? - ???? ??? ???? ?.?. 058354242.docx) -- C:\Users\TDW\Desktop\עבודה בקורס גרוש, גלות וגאולה - מלכה כהן נהרי מ.ז. 058354242.docx
[2016-07-05 19:15:00 | 000,033,825 | ---- | M] ()(C:\Users\TDW\Desktop\???? ??? - ???? ????? ???? ???????? ???? ?????? - ???? ???-????, ?.?. 058354242.docx) -- C:\Users\TDW\Desktop\מבחן בית - קורס אנוסי ספרד ופורטוגל לאחר הגירוש - מלכה כהן-נהרי, מ.ז. 058354242.docx
[2016-07-03 17:40:46 | 000,033,825 | ---- | C] ()(C:\Users\TDW\Desktop\???? ??? - ???? ????? ???? ???????? ???? ?????? - ???? ???-????, ?.?. 058354242.docx) -- C:\Users\TDW\Desktop\מבחן בית - קורס אנוסי ספרד ופורטוגל לאחר הגירוש - מלכה כהן-נהרי, מ.ז. 058354242.docx
[2016-05-23 18:55:41 | 000,032,908 | ---- | M] ()(C:\Users\TDW\Desktop\????? - ????? ???? ????? ?????? ???????? - ???? ???-????, ?.?. 058354242.docx) -- C:\Users\TDW\Desktop\תיקון - עבודת סיום בקורס תעודות ופרשנותן - מלכה כהן-נהרי, מ.ז. 058354242.docx
[2016-05-19 23:13:59 | 000,015,340 | ---- | M] ()(C:\Users\TDW\Desktop\????? ???? ?????.docx) -- C:\Users\TDW\Desktop\עבודת סיום בקורס.docx
[2016-05-19 23:13:59 | 000,015,340 | ---- | C] ()(C:\Users\TDW\Desktop\????? ???? ?????.docx) -- C:\Users\TDW\Desktop\עבודת סיום בקורס.docx
[2016-05-19 23:13:59 | 000,000,162 | -H-- | M] ()(C:\Users\TDW\Desktop\~$??? ???? ?????.docx) -- C:\Users\TDW\Desktop\~$ודת סיום בקורס.docx
[2016-05-19 23:13:59 | 000,000,162 | -H-- | C] ()(C:\Users\TDW\Desktop\~$??? ???? ?????.docx) -- C:\Users\TDW\Desktop\~$ודת סיום בקורס.docx
[2016-05-19 16:19:46 | 000,032,908 | ---- | C] ()(C:\Users\TDW\Desktop\????? - ????? ???? ????? ?????? ???????? - ???? ???-????, ?.?. 058354242.docx) -- C:\Users\TDW\Desktop\תיקון - עבודת סיום בקורס תעודות ופרשנותן - מלכה כהן-נהרי, מ.ז. 058354242.docx
[2016-05-17 19:13:04 | 000,048,944 | ---- | M] ()(C:\Users\TDW\Desktop\???? ???-???? - ???? ??? ????? ???????, ??????, ?????? ?????????.docx) -- C:\Users\TDW\Desktop\מלכה כהן-נהרי - מבחן בית בקורס לאומיות, ציונות, תולדות ההתיישבות.docx
[2016-05-08 18:37:45 | 000,036,868 | ---- | M] ()(C:\Users\TDW\Desktop\???? ??? ????? ????? ????????? ?????? - ???? ???-????, ?.?. 058354242.docx) -- C:\Users\TDW\Desktop\מבחן בית בקורס זרמים ופלורליזם ביהדות - מלכה כהן-נהרי, מ.ז. 058354242.docx
[2016-04-20 23:33:04 | 000,014,943 | ---- | M] ()(C:\Users\TDW\Desktop\????? ?????? ??????? ????? ?????? ?????? ???? ???? ????.docx) -- C:\Users\TDW\Desktop\שחרור החסמים הגדולים ביותר למציאת זוגיות שלום מטלי וחנן.docx
[2016-04-20 23:33:04 | 000,014,943 | ---- | C] ()(C:\Users\TDW\Desktop\????? ?????? ??????? ????? ?????? ?????? ???? ???? ????.docx) -- C:\Users\TDW\Desktop\שחרור החסמים הגדולים ביותר למציאת זוגיות שלום מטלי וחנן.docx
[2016-04-12 12:12:19 | 000,036,868 | ---- | C] ()(C:\Users\TDW\Desktop\???? ??? ????? ????? ????????? ?????? - ???? ???-????, ?.?. 058354242.docx) -- C:\Users\TDW\Desktop\מבחן בית בקורס זרמים ופלורליזם ביהדות - מלכה כהן-נהרי, מ.ז. 058354242.docx
[2016-02-21 20:43:28 | 000,103,537 | ---- | M] ()(C:\Users\TDW\Desktop\?????? ?????? 16.pdf) -- C:\Users\TDW\Desktop\הגיחון פברואר 16.pdf
[2016-02-21 20:43:28 | 000,103,537 | ---- | C] ()(C:\Users\TDW\Desktop\?????? ?????? 16.pdf) -- C:\Users\TDW\Desktop\הגיחון פברואר 16.pdf
[2016-02-17 17:44:29 | 000,034,338 | ---- | M] ()(C:\Users\TDW\Desktop\???? ???-???? - ???? ??? ????? ????? ??????.docx) -- C:\Users\TDW\Desktop\מלכה כהן-נהרי - מבחן בית בקורס מהמרה לגירוש.docx
[2016-02-17 00:47:49 | 000,056,992 | ---- | M] ()(C:\Users\TDW\Desktop\???? ????? ?????? - ????. ???? ???? ????.docx) -- C:\Users\TDW\Desktop\קורס מהמרה לגירוש - פרופ. רינה לוין מלמד.docx
[2016-02-16 15:56:11 | 000,056,992 | ---- | C] ()(C:\Users\TDW\Desktop\???? ????? ?????? - ????. ???? ???? ????.docx) -- C:\Users\TDW\Desktop\קורס מהמרה לגירוש - פרופ. רינה לוין מלמד.docx
[2016-02-16 15:33:21 | 000,034,338 | ---- | C] ()(C:\Users\TDW\Desktop\???? ???-???? - ???? ??? ????? ????? ??????.docx) -- C:\Users\TDW\Desktop\מלכה כהן-נהרי - מבחן בית בקורס מהמרה לגירוש.docx
[2016-02-02 23:45:28 | 000,012,983 | ---- | M] ()(C:\Users\TDW\Desktop\160 ???? ??????.docx) -- C:\Users\TDW\Desktop\160 לפני הספירה.docx
[2016-02-02 23:45:28 | 000,012,983 | ---- | C] ()(C:\Users\TDW\Desktop\160 ???? ??????.docx) -- C:\Users\TDW\Desktop\160 לפני הספירה.docx
[2015-11-24 20:46:52 | 002,250,992 | ---- | M] ()(C:\Users\TDW\Desktop\??? ????.rtf) -- C:\Users\TDW\Desktop\אמא קורס.rtf
[2015-11-24 20:46:51 | 002,250,992 | ---- | C] ()(C:\Users\TDW\Desktop\??? ????.rtf) -- C:\Users\TDW\Desktop\אמא קורס.rtf
[2015-11-24 12:59:20 | 000,048,944 | ---- | C] ()(C:\Users\TDW\Desktop\???? ???-???? - ???? ??? ????? ???????, ??????, ?????? ?????????.docx) -- C:\Users\TDW\Desktop\מלכה כהן-נהרי - מבחן בית בקורס לאומיות, ציונות, תולדות ההתיישבות.docx
[2015-11-17 21:54:45 | 000,100,707 | ---- | M] ()(C:\Users\TDW\Desktop\??' ?????? ??_?.pdf) -- C:\Users\TDW\Desktop\חב' הגיחון בע_מ.pdf
[2015-11-17 21:54:45 | 000,100,707 | ---- | C] ()(C:\Users\TDW\Desktop\??' ?????? ??_?.pdf) -- C:\Users\TDW\Desktop\חב' הגיחון בע_מ.pdf
[2015-11-12 20:12:45 | 000,174,590 | ---- | M] ()(C:\Users\TDW\Desktop\???? ??????.pdf) -- C:\Users\TDW\Desktop\מחיר למשתכן.pdf
[2015-11-12 20:12:45 | 000,174,590 | ---- | C] ()(C:\Users\TDW\Desktop\???? ??????.pdf) -- C:\Users\TDW\Desktop\מחיר למשתכן.pdf
[2015-11-06 13:49:25 | 000,000,000 | --SD | M](C:\Users\TDW\Documents\?????? ??????? ???) -- C:\Users\TDW\Documents\מקורות הנתונים שלי
[2015-11-06 13:49:25 | 000,000,000 | --SD | C](C:\Users\TDW\Documents\?????? ??????? ???) -- C:\Users\TDW\Documents\מקורות הנתונים שלי
[2015-10-29 21:51:07 | 001,029,078 | ---- | M] ()(C:\Users\TDW\Desktop\?????? ?????? ?????? 29.01.12.pdf) -- C:\Users\TDW\Desktop\המדריך למציאת זוגיות 29.01.12.pdf
[2015-10-29 21:51:02 | 001,029,078 | ---- | C] ()(C:\Users\TDW\Desktop\?????? ?????? ?????? 29.01.12.pdf) -- C:\Users\TDW\Desktop\המדריך למציאת זוגיות 29.01.12.pdf
[2015-08-31 19:34:33 | 000,000,000 | ---D | M](C:\Users\TDW\Desktop\??? ??????) -- C:\Users\TDW\Desktop\אמא קורסים
[2015-06-08 21:50:52 | 000,000,000 | ---D | C](C:\Users\TDW\Desktop\??? ??????) -- C:\Users\TDW\Desktop\אמא קורסים
[2015-05-26 20:13:49 | 000,039,844 | ---- | M] ()(C:\Users\TDW\Documents\??? ????? ??????? - ????? ???? ????, ???? ???-????.docx) -- C:\Users\TDW\Documents\שות כמקור היסטורי - עבודת סיום קורס, מלכה כהן-נהרי.docx
[2015-05-20 13:01:33 | 000,039,844 | ---- | C] ()(C:\Users\TDW\Documents\??? ????? ??????? - ????? ???? ????, ???? ???-????.docx) -- C:\Users\TDW\Documents\שות כמקור היסטורי - עבודת סיום קורס, מלכה כהן-נהרי.docx
[2013-06-27 17:52:35 | 000,000,193 | ---- | M] ()(C:\Users\TDW\Documents\???? ???? ????.rtf) -- C:\Users\TDW\Documents\ססמא יאיר דואל.rtf
[2013-06-27 17:52:35 | 000,000,193 | ---- | C] ()(C:\Users\TDW\Documents\???? ???? ????.rtf) -- C:\Users\TDW\Documents\ססמא יאיר דואל.rtf
[2013-06-19 21:54:12 | 000,016,837 | ---- | M] ()(C:\Users\TDW\Documents\?????? - ????.docx) -- C:\Users\TDW\Documents\וובינר - לירז.docx
[2013-06-19 21:54:12 | 000,016,837 | ---- | C] ()(C:\Users\TDW\Documents\?????? - ????.docx) -- C:\Users\TDW\Documents\וובינר - לירז.docx
[2013-06-15 22:21:25 | 000,016,927 | ---- | M] ()(C:\Users\TDW\Documents\??????? - ???????.docx) -- C:\Users\TDW\Documents\ביקורים - תיאומים.docx
[2013-06-15 22:21:24 | 000,016,927 | ---- | C] ()(C:\Users\TDW\Documents\??????? - ???????.docx) -- C:\Users\TDW\Documents\ביקורים - תיאומים.docx
========== Alternate Data Streams ==========
@Alternate Data Stream - 6144 bytes -> C:\Windows\Cursors\arrow_n.cur:NEDTA.DAT
@Alternate Data Stream - 4 bytes -> C:\temp:rnd.dat
@Alternate Data Stream - 4 bytes -> C:\temp:pid2
@Alternate Data Stream - 4 bytes -> C:\temp:pid1
@Alternate Data Stream - 22 bytes -> C:\temp:srv
< End of report >