Solved Strange behavior

Hello PatL
As per previous advice from Jmarket and myself, your logs show clearly you are running Commodo and Avast. You have been advised to remove one of these and you say Commodo is not listed in your add remove programs. This would be another reason to remove Commodo.

See here
Follow the uninstall instructions only, do not reinstall it.

For us to continue we will insist you remove either Avast or Commodo, again recommend removingy Commodo. It is possible the inappropriate use of the multitude of security software active on your machine may have been in some way responsible for the issues you raise by damaging your operating system or indeed if malware was removed or still remains. Please also remove the following software whilst we clean your machine.

9 lab removal tool
Eset online scanner
Herd Protect
Hitman pro
Voodoo shield

Ensure you have any keys for any paid for programs before uninstall.

This will leave Avast as your security protection until we finish.🙂
Hello Gus,

All programs have been uninstalled as requested. Here are a Fresh FRST & Addition for review. What is the next step?

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-11-2017
Ran by Patrick (administrator) on PATRICK-PC (21-11-2017 17:34:29)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Patrick & Owner (Available Profiles: Patrick & Owner & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\FreedomeService.exe
(Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Ruiware) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(The OpenVPN Project) C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\openvpn.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\Freedome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-08] (AVAST Software)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM\...\RunOnce: [000ClearPageFileAtShutdown] => cmd /c reg import "C:\Users\Patrick\AppData\Local\000ClearPageFileAtShutdown" & cmd /c del "C:\Users\Patrick\AppData\Local\000ClearPageFileAtShutdown"
HKLM\...\RunOnce: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] => C:\ProgramData\cis7D3A.exe [4784832 2017-08-29] (COMODO)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1492466166-1735938548-1690570200-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1223560 2017-05-07] (Ruiware)
HKU\S-1-5-21-1492466166-1735938548-1690570200-1000\...\Run: [Wipe Maintance] => C:\Program Files\Wipe\net1.exe [880920 2017-10-07] (
HKU\S-1-5-21-1492466166-1735938548-1690570200-1000\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1223560 2017-05-07] (Ruiware)
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\Policies\Explorer: [NoInstrumentation] 1
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\MountPoints2: {5a55a7a1-ab52-11e7-9aeb-00256460faa9} - E:\unlock.exe autoplay=true
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\MountPoints2: {613dae09-aaa4-11e7-8a92-00256460faa9} - "E:\WD Drive Unlock.exe" autoplay=true
BootExecute: autocheck autochk *

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{05791D1D-051A-4ECE-A4F5-2DC4F9998DD0}: [DhcpNameServer]
Tcpip\..\Interfaces\{444988B6-9931-4F66-8E63-A199AE9754F2}: [NameServer]
Tcpip\..\Interfaces\{539CB6FE-A5AF-4637-8F18-2DC6A160B884}: [NameServer]
Tcpip\..\Interfaces\{539CB6FE-A5AF-4637-8F18-2DC6A160B884}: [DhcpNameServer]
Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer]

Internet Explorer:
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
HKU\S-1-5-21-1492466166-1735938548-1690570200-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-1492466166-1735938548-1690570200-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://{searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-11-03] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-11-03] (AVAST Software)

FF DefaultProfile: xxwz7xvm.default
FF ProfilePath: C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default [2017-11-21]
FF Homepage: Mozilla\Firefox\Profiles\xxwz7xvm.default -> hxxps://
FF NewTab: Mozilla\Firefox\Profiles\xxwz7xvm.default -> hxxps://
FF Extension: (LanguageTool - Grammar and Style Checker) - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default\Extensions\ [2017-11-15]
FF Extension: (uBlock Origin) - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default\Extensions\ [2017-11-15]
FF Extension: (Avast Online Security) - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default\Extensions\ [2017-10-13]
FF Extension: (Video DownloadHelper) - C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-11-19]

CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7549928 2017-11-03] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-08] (AVAST Software)
R2 Freedome Service; C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\FreedomeService.exe [592352 2017-10-05] (F-Secure Corporation)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [294168 2017-10-07] (Reason Software Company Inc.)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [183584 2017-11-03] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321032 2017-10-31] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [198968 2017-10-31] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343288 2017-10-31] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57728 2017-10-31] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [47008 2017-11-03] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [148288 2017-11-03] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110376 2017-11-03] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84416 2017-11-03] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026232 2017-11-03] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [455376 2017-11-15] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [203976 2017-11-03] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [364464 2017-11-03] (AVAST Software)
R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd)
R3 fsfreedometap; C:\Windows\System32\DRIVERS\fsfreedometap.sys [34344 2017-10-05] (The OpenVPN Project)
S3 pbfilter; C:\Program Files\PeerBlock\pbfilter.sys [22600 2014-01-14] ()
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
S1 mbamchameleon; \??\C:\Windows\system32\drivers\mbamchameleon.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 VSScanner; system32\DRIVERS\vsscanner.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-21 17:33 - 2017-11-21 17:33 - 002391552 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2017-11-21 17:21 - 2017-11-21 17:23 - 000000000 ____D C:\Users\Patrick\AppData\LocalLow\Mozilla
2017-11-21 17:21 - 2017-11-21 17:21 - 000064424 _____ C:\Users\Patrick\AppData\Local\GDIPFONTCACHEV1.DAT
2017-11-21 17:21 - 2017-11-21 17:21 - 000000000 ____D C:\Users\Patrick\AppData\Local\Mozilla
2017-11-21 17:19 - 2017-11-21 17:19 - 000000416 _____ C:\Windows\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}.job
2017-11-21 17:19 - 2017-08-29 04:56 - 000365248 _____ (COMODO) C:\ProgramData\cmdres.dll
2017-11-21 17:19 - 2017-08-29 04:52 - 004784832 _____ (COMODO) C:\ProgramData\cis7D3A.exe
2017-11-21 17:18 - 2017-11-21 17:18 - 000000000 ____D C:\ProgramData\Shared Space
2017-11-21 17:16 - 2017-11-21 17:22 - 000216124 _____ C:\Windows\ntbtlog.txt
2017-11-21 13:48 - 2017-11-21 13:49 - 000295296 _____ C:\Windows\system32\FNTCACHE.DAT
2017-11-21 13:40 - 2017-11-21 13:40 - 000000344 _____ C:\Users\Patrick\AppData\Local\000ClearPageFileAtShutdown
2017-11-20 13:36 - 2017-11-20 18:32 - 000000000 ____D C:\AdsFix
2017-11-20 13:34 - 2017-11-20 13:35 - 005985704 _____ (SosVirus) C:\Users\Owner\Desktop\AdsFix.exe
2017-11-20 13:33 - 2017-11-20 13:33 - 003983272 _____ (SosVirus) C:\Users\Owner\Desktop\quickdiag_3_22.10.17.1.exe
2017-11-19 22:14 - 2017-11-19 22:22 - 000000000 ____D C:\AdwCleaner
2017-11-19 21:40 - 2017-11-21 17:34 - 000000000 ____D C:\FRST
2017-11-19 20:48 - 2017-11-19 20:48 - 000000000 ____D C:\RegBackup
2017-11-19 14:23 - 2017-11-19 14:41 - 670426613 _____ C:\Users\Patrick\Downloads\Planet_Hulk_[Graphic_Audio].m4b
2017-11-19 13:25 - 2017-11-19 13:25 - 000000637 _____ C:\Users\Patrick\AppData\Local\ZHPFixReport.txt
2017-11-19 11:20 - 2017-11-21 13:50 - 031578292 ____H C:\Windows\system32\Drivers\etc\HOSTS.ehm.bak
2017-11-19 10:31 - 2017-11-19 10:34 - 000000794 _____ C:\Users\Patrick\Desktop\ZHPCleaner.lnk
2017-11-19 10:30 - 2017-11-19 10:30 - 002973056 _____ C:\Users\Owner\Desktop\ZHPCleaner.exe
2017-11-19 10:22 - 2017-11-19 10:22 - 000000000 ____D C:\Users\Owner\Desktop\Quarantine
2017-11-19 10:21 - 2017-11-19 10:21 - 003061760 _____ (Nicolas Coolman) C:\Users\Owner\Desktop\ZHPFix.exe
2017-11-19 10:18 - 2017-11-19 10:18 - 003061760 _____ (Nicolas Coolman) C:\Users\Patrick\Downloads\ZHPFix.exe
2017-11-19 09:56 - 2017-11-19 14:56 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\ZHP
2017-11-19 09:56 - 2017-11-19 10:31 - 000000000 ____D C:\Users\Patrick\AppData\Local\ZHP
2017-11-19 09:56 - 2017-11-19 09:56 - 000000784 _____ C:\Users\Patrick\Desktop\ZHPDiag.lnk
2017-11-19 09:50 - 2017-11-19 15:00 - 000000000 ____D C:\Users\Owner\AppData\Local\CrashDumps
2017-11-19 09:49 - 2017-11-19 09:49 - 002928512 _____ C:\Users\Owner\Desktop\ZHPDiag3.exe
2017-11-18 20:59 - 2017-11-18 20:59 - 000255928 _____ (Malwarebytes) C:\Windows\system32\Drivers\4B53E2E4.sys
2017-11-18 12:08 - 2017-11-20 21:31 - 000028159 _____ C:\Users\Owner\Desktop\Addition.txt
2017-11-18 12:05 - 2017-11-21 17:35 - 000010470 _____ C:\Users\Owner\Desktop\FRST.txt
2017-11-17 12:43 - 2010-06-02 04:55 - 000527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2017-11-17 12:43 - 2010-06-02 04:55 - 000518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2017-11-17 12:43 - 2010-06-02 04:55 - 000239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2017-11-17 12:43 - 2010-06-02 04:55 - 000176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2017-11-17 12:43 - 2010-06-02 04:55 - 000077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2017-11-17 12:43 - 2010-06-02 04:55 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 002526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 002401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 002106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 001998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 001907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 001868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 000511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 000470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 000276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2017-11-17 12:43 - 2010-05-26 11:41 - 000248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2017-11-17 12:43 - 2010-02-04 10:01 - 000530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2017-11-17 12:43 - 2010-02-04 10:01 - 000528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2017-11-17 12:43 - 2010-02-04 10:01 - 000238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2017-11-17 12:43 - 2010-02-04 10:01 - 000176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2017-11-17 12:43 - 2010-02-04 10:01 - 000078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2017-11-17 12:43 - 2010-02-04 10:01 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2017-11-17 12:43 - 2010-02-04 10:01 - 000024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2017-11-17 12:43 - 2010-02-04 10:01 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2017-11-17 12:43 - 2009-09-04 17:44 - 000517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2017-11-17 12:43 - 2009-09-04 17:44 - 000515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2017-11-17 12:43 - 2009-09-04 17:44 - 000238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2017-11-17 12:43 - 2009-09-04 17:44 - 000176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2017-11-17 12:43 - 2009-09-04 17:44 - 000073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2017-11-17 12:43 - 2009-09-04 17:44 - 000069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 005554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 005501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 002582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 002475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 001974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 001892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 000523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 000285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2017-11-17 12:43 - 2009-09-04 17:29 - 000235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2017-11-17 12:43 - 2009-03-16 14:18 - 000521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2017-11-17 12:43 - 2009-03-16 14:18 - 000517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2017-11-17 12:43 - 2009-03-16 14:18 - 000235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2017-11-17 12:43 - 2009-03-16 14:18 - 000174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2017-11-17 12:43 - 2009-03-16 14:18 - 000024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2017-11-17 12:43 - 2009-03-16 14:18 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2017-11-17 12:43 - 2009-03-09 15:27 - 005425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2017-11-17 12:43 - 2009-03-09 15:27 - 004178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2017-11-17 12:43 - 2009-03-09 15:27 - 002430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2017-11-17 12:43 - 2009-03-09 15:27 - 001846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2017-11-17 12:43 - 2009-03-09 15:27 - 000520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2017-11-17 12:43 - 2009-03-09 15:27 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2017-11-17 12:43 - 2008-10-15 06:22 - 002605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2017-11-17 12:43 - 2008-10-15 06:22 - 002036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2017-11-17 12:43 - 2008-10-15 06:22 - 000519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2017-11-17 12:43 - 2008-10-15 06:22 - 000452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2017-11-17 12:42 - 2008-10-27 10:04 - 000518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2017-11-17 12:42 - 2008-10-27 10:04 - 000514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2017-11-17 12:42 - 2008-10-27 10:04 - 000235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2017-11-17 12:42 - 2008-10-27 10:04 - 000175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2017-11-17 12:42 - 2008-10-27 10:04 - 000074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2017-11-17 12:42 - 2008-10-27 10:04 - 000070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2017-11-17 12:42 - 2008-10-27 10:04 - 000025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2017-11-17 12:42 - 2008-10-27 10:04 - 000023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2017-11-17 12:42 - 2008-10-15 06:22 - 005631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2017-11-17 12:42 - 2008-10-15 06:22 - 004379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2017-11-17 12:42 - 2008-07-31 10:41 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2017-11-17 12:42 - 2008-07-31 10:41 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2017-11-17 12:42 - 2008-07-31 10:41 - 000072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2017-11-17 12:42 - 2008-07-31 10:41 - 000068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2017-11-17 12:42 - 2008-07-31 10:40 - 000513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2017-11-17 12:42 - 2008-07-31 10:40 - 000509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2017-11-17 12:42 - 2008-07-10 11:01 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2017-11-17 12:42 - 2008-07-10 11:00 - 004992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2017-11-17 12:42 - 2008-07-10 11:00 - 001942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2017-11-17 12:42 - 2008-07-10 11:00 - 001493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2017-11-17 12:42 - 2008-07-10 11:00 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2017-11-17 12:36 - 2017-11-17 12:36 - 000001706 _____ C:\Users\Public\Desktop\Star Wars - Knights of the Old Republic.lnk
2017-11-15 16:54 - 2017-11-15 16:54 - 000000000 ____D C:\ProgramData\Emsisoft
2017-11-15 14:49 - 2017-11-15 14:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wipe
2017-11-15 14:42 - 2017-11-15 14:42 - 015162120 _____ (Goversoft LLC) C:\Users\Owner\Desktop\PrivaZer.exe
2017-11-15 13:52 - 2017-11-15 13:52 - 000001438 _____ C:\Users\Owner\Desktop\SpeedFan.lnk
2017-11-15 11:50 - 2017-11-15 11:50 - 000001264 _____ C:\Users\Patrick\Desktop\FurMark.lnk
2017-11-15 11:50 - 2017-11-15 11:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D
2017-11-15 11:50 - 2017-11-15 11:50 - 000000000 ____D C:\Program Files (x86)\Geeks3D
2017-11-15 11:31 - 2017-11-15 11:31 - 000000000 ___SD C:\Windows\system32\CompatTel
2017-11-15 11:01 - 2008-07-10 11:00 - 003851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2017-11-15 11:01 - 2008-05-30 14:19 - 000511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2017-11-15 11:01 - 2008-05-30 14:19 - 000507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2017-11-15 11:01 - 2008-05-30 14:18 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2017-11-15 11:01 - 2008-05-30 14:18 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2017-11-15 11:01 - 2008-05-30 14:17 - 000068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2017-11-15 11:01 - 2008-05-30 14:17 - 000065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2017-11-15 11:01 - 2008-05-30 14:17 - 000025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2017-11-15 11:01 - 2008-05-30 14:16 - 000028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2017-11-15 11:01 - 2008-05-30 14:11 - 004991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2017-11-15 11:01 - 2008-05-30 14:11 - 003850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2017-11-15 11:01 - 2008-05-30 14:11 - 001941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2017-11-15 11:01 - 2008-05-30 14:11 - 001491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2017-11-15 11:01 - 2008-05-30 14:11 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2017-11-15 11:01 - 2008-05-30 14:11 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2017-11-15 11:01 - 2008-03-05 16:04 - 000489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2017-11-15 11:01 - 2008-03-05 16:03 - 000479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2017-11-15 11:01 - 2008-03-05 16:03 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2017-11-15 11:01 - 2008-03-05 16:03 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2017-11-15 11:01 - 2008-03-05 16:00 - 000028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2017-11-15 11:01 - 2008-03-05 16:00 - 000025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2017-11-15 11:01 - 2008-03-05 15:56 - 004910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2017-11-15 11:01 - 2008-03-05 15:56 - 003786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2017-11-15 11:01 - 2008-03-05 15:56 - 001860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2017-11-15 11:01 - 2008-03-05 15:56 - 001420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2017-11-15 11:01 - 2008-02-05 23:07 - 000529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2017-11-15 11:01 - 2008-02-05 23:07 - 000462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2017-11-15 11:01 - 2007-10-22 03:40 - 000411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2017-11-15 11:01 - 2007-10-22 03:39 - 000267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2017-11-15 11:01 - 2007-10-12 15:14 - 005081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2017-11-15 11:01 - 2007-10-12 15:14 - 003734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2017-11-15 11:01 - 2007-10-12 15:14 - 002006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2017-11-15 11:01 - 2007-10-12 15:14 - 001374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2017-11-15 11:01 - 2007-10-02 09:56 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2017-11-15 11:01 - 2007-10-02 09:56 - 000444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2017-11-15 11:00 - 2007-10-22 03:37 - 000021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2017-11-15 11:00 - 2007-10-22 03:37 - 000017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2017-11-15 11:00 - 2007-07-20 00:57 - 000411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2017-11-15 11:00 - 2007-07-20 00:57 - 000267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2017-11-15 11:00 - 2007-07-19 18:14 - 005073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2017-11-15 11:00 - 2007-07-19 18:14 - 003727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2017-11-15 11:00 - 2007-07-19 18:14 - 001985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2017-11-15 11:00 - 2007-07-19 18:14 - 001358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2017-11-15 11:00 - 2007-07-19 18:14 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2017-11-15 11:00 - 2007-07-19 18:14 - 000444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2017-11-15 11:00 - 2007-06-20 20:49 - 000409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2017-11-15 11:00 - 2007-06-20 20:46 - 000266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2017-11-15 11:00 - 2007-05-16 16:45 - 004496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2017-11-15 11:00 - 2007-05-16 16:45 - 003497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2017-11-15 11:00 - 2007-05-16 16:45 - 001401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2017-11-15 11:00 - 2007-05-16 16:45 - 001124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2017-11-15 11:00 - 2007-05-16 16:45 - 000506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2017-11-15 11:00 - 2007-05-16 16:45 - 000443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2017-11-15 11:00 - 2007-04-04 18:55 - 000403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2017-11-15 11:00 - 2007-04-04 18:55 - 000261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2017-11-15 11:00 - 2007-04-04 18:54 - 000107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2017-11-15 11:00 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2017-11-15 11:00 - 2007-03-15 16:57 - 000506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2017-11-15 11:00 - 2007-03-15 16:57 - 000443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2017-11-15 11:00 - 2007-03-12 16:42 - 004494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2017-11-15 11:00 - 2007-03-12 16:42 - 003495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2017-11-15 11:00 - 2007-03-12 16:42 - 001400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2017-11-15 11:00 - 2007-03-12 16:42 - 001123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2017-11-15 11:00 - 2007-03-05 12:42 - 000017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2017-11-15 11:00 - 2007-03-05 12:42 - 000015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2017-11-15 11:00 - 2007-01-24 15:27 - 000393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2017-11-15 11:00 - 2007-01-24 15:27 - 000255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2017-11-15 11:00 - 2006-12-08 12:02 - 000251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2017-11-15 11:00 - 2006-12-08 12:00 - 000390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2017-11-15 11:00 - 2006-11-29 13:06 - 004398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2017-11-15 11:00 - 2006-11-29 13:06 - 003426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2017-11-15 11:00 - 2006-11-29 13:06 - 000469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2017-11-15 11:00 - 2006-11-29 13:06 - 000440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2017-11-15 11:00 - 2006-09-28 16:05 - 003977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2017-11-15 11:00 - 2006-09-28 16:05 - 002414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2017-11-15 11:00 - 2006-09-28 16:05 - 000237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2017-11-15 11:00 - 2006-09-28 16:04 - 000364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2017-11-15 11:00 - 2006-07-28 09:31 - 000083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2017-11-15 11:00 - 2006-07-28 09:30 - 000363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2017-11-15 11:00 - 2006-07-28 09:30 - 000236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2017-11-15 11:00 - 2006-07-28 09:30 - 000062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2017-11-15 11:00 - 2006-05-31 07:24 - 000230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2017-11-15 11:00 - 2006-05-31 07:22 - 000354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2017-11-15 11:00 - 2006-03-31 12:41 - 003927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2017-11-15 11:00 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2017-11-15 11:00 - 2006-03-31 12:40 - 000352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2017-11-15 11:00 - 2006-03-31 12:39 - 000229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2017-11-15 11:00 - 2006-03-31 12:39 - 000083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2017-11-15 11:00 - 2006-03-31 12:39 - 000062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2017-11-15 11:00 - 2006-02-03 08:43 - 003830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2017-11-15 11:00 - 2006-02-03 08:43 - 002332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2017-11-15 11:00 - 2006-02-03 08:42 - 000355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2017-11-15 11:00 - 2006-02-03 08:42 - 000230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2017-11-15 11:00 - 2006-02-03 08:41 - 000016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2017-11-15 11:00 - 2006-02-03 08:41 - 000014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2017-11-15 11:00 - 2005-12-05 18:09 - 003815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2017-11-15 11:00 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2017-11-15 11:00 - 2005-07-22 19:59 - 003807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2017-11-15 11:00 - 2005-07-22 19:59 - 002319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2017-11-15 11:00 - 2005-05-26 15:34 - 003767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2017-11-15 11:00 - 2005-05-26 15:34 - 002297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2017-11-15 11:00 - 2005-03-18 17:19 - 003823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2017-11-15 11:00 - 2005-03-18 17:19 - 002337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2017-11-15 11:00 - 2005-02-05 19:45 - 003544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2017-11-15 11:00 - 2005-02-05 19:45 - 002222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2017-11-15 10:56 - 2017-11-15 10:56 - 000000000 ____D C:\Windows\SysWOW64\directx
2017-11-15 10:56 - 2017-11-15 10:56 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2017-11-15 10:55 - 2017-11-15 11:10 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2017-11-15 10:55 - 2017-11-15 10:55 - 000001102 _____ C:\Users\Patrick\Desktop\MSI Afterburner.lnk
2017-11-15 10:55 - 2017-11-15 10:55 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2017-11-15 10:54 - 2017-11-15 11:01 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2017-11-15 10:53 - 2017-10-17 23:31 - 000395976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-11-15 10:53 - 2017-10-17 22:45 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-11-15 10:53 - 2017-10-17 18:06 - 000344064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2017-11-15 10:53 - 2017-10-17 18:06 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2017-11-15 10:53 - 2017-10-17 18:06 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2017-11-15 10:53 - 2017-10-17 18:06 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2017-11-15 10:53 - 2017-10-17 18:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2017-11-15 10:53 - 2017-10-17 18:06 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2017-11-15 10:53 - 2017-10-17 18:06 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2017-11-15 10:53 - 2017-10-16 15:07 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-11-15 10:53 - 2017-10-16 14:34 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-11-15 10:53 - 2017-10-16 13:55 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-11-15 10:53 - 2017-10-14 00:38 - 025731584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-11-15 10:53 - 2017-10-14 00:23 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-11-15 10:53 - 2017-10-14 00:23 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-11-15 10:53 - 2017-10-14 00:13 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-11-15 10:53 - 2017-10-14 00:12 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-11-15 10:53 - 2017-10-14 00:11 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-11-15 10:53 - 2017-10-14 00:11 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-11-15 10:53 - 2017-10-14 00:11 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-11-15 10:53 - 2017-10-14 00:11 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-11-15 10:53 - 2017-10-14 00:09 - 005979648 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-11-15 10:53 - 2017-10-14 00:05 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-11-15 10:53 - 2017-10-14 00:04 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-11-15 10:53 - 2017-10-14 00:02 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-11-15 10:53 - 2017-10-14 00:01 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-11-15 10:53 - 2017-10-14 00:01 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-11-15 10:53 - 2017-10-14 00:01 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-11-15 10:53 - 2017-10-14 00:00 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-11-15 10:53 - 2017-10-13 23:55 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-11-15 10:53 - 2017-10-13 23:53 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-11-15 10:53 - 2017-10-13 23:47 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-11-15 10:53 - 2017-10-13 23:47 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-11-15 10:53 - 2017-10-13 23:46 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-11-15 10:53 - 2017-10-13 23:43 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-11-15 10:53 - 2017-10-13 23:43 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-11-15 10:53 - 2017-10-13 23:41 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-11-15 10:53 - 2017-10-13 23:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-11-15 10:53 - 2017-10-13 23:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-11-15 10:53 - 2017-10-13 23:30 - 015266816 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-11-15 10:53 - 2017-10-13 23:30 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-11-15 10:53 - 2017-10-13 23:29 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-11-15 10:53 - 2017-10-13 23:28 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-11-15 10:53 - 2017-10-13 23:27 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-11-15 10:53 - 2017-10-13 23:21 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-11-15 10:53 - 2017-10-13 23:14 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-11-15 10:53 - 2017-10-13 23:09 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-11-15 10:53 - 2017-10-13 23:03 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-11-15 10:53 - 2017-10-13 22:58 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-11-15 10:53 - 2017-10-13 22:53 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-11-15 10:53 - 2017-10-13 22:53 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-11-15 10:53 - 2017-10-13 22:52 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-11-15 10:53 - 2017-10-13 22:52 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-11-15 10:53 - 2017-10-13 22:51 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-11-15 10:53 - 2017-10-13 22:50 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-11-15 10:53 - 2017-10-13 22:47 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-11-15 10:53 - 2017-10-13 22:47 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-11-15 10:53 - 2017-10-13 22:46 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-11-15 10:53 - 2017-10-13 22:45 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-11-15 10:53 - 2017-10-13 22:45 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-11-15 10:53 - 2017-10-13 22:45 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-11-15 10:53 - 2017-10-13 22:38 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-11-15 10:53 - 2017-10-13 22:35 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-11-15 10:53 - 2017-10-13 22:35 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-11-15 10:53 - 2017-10-13 22:34 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-11-15 10:53 - 2017-10-13 22:33 - 004542464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-11-15 10:53 - 2017-10-13 22:33 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-11-15 10:53 - 2017-10-13 22:32 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-11-15 10:53 - 2017-10-13 22:31 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-11-15 10:53 - 2017-10-13 22:30 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-11-15 10:53 - 2017-10-13 22:28 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-11-15 10:53 - 2017-10-13 22:25 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-11-15 10:53 - 2017-10-13 22:24 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-11-15 10:53 - 2017-10-13 22:23 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-11-15 10:53 - 2017-10-13 22:23 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-11-15 10:53 - 2017-10-13 22:10 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-11-15 10:53 - 2017-10-13 22:07 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-11-15 10:53 - 2017-10-13 22:04 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-11-15 10:53 - 2017-10-11 16:58 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 014635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2017-11-15 10:53 - 2017-10-11 16:55 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2017-11-15 10:53 - 2017-10-11 16:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2017-11-15 10:53 - 2017-10-11 16:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2017-11-15 10:53 - 2017-10-11 16:40 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-11-15 10:53 - 2017-10-11 16:39 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-11-15 10:53 - 2017-10-11 16:38 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-11-15 10:53 - 2017-10-11 16:38 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-11-15 10:53 - 2017-10-11 16:37 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2017-11-15 10:53 - 2017-10-11 16:37 - 011410944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-11-15 10:53 - 2017-10-11 16:37 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-11-15 10:53 - 2017-10-11 16:26 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-11-15 10:53 - 2017-10-11 16:26 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-11-15 10:53 - 2017-10-11 16:25 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-11-15 10:53 - 2017-10-11 16:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-11-15 10:53 - 2017-10-11 16:24 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2017-11-15 10:53 - 2017-10-11 16:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2017-11-15 10:53 - 2017-10-11 16:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2017-11-15 10:53 - 2017-10-11 16:20 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys
2017-11-15 10:53 - 2017-10-11 16:16 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-11-15 10:49 - 2017-10-17 18:34 - 000134376 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2017-11-15 10:49 - 2017-10-17 18:30 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-11-15 10:49 - 2017-10-15 14:04 - 000407392 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2017-11-15 10:49 - 2017-10-04 05:04 - 002023936 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2017-11-15 10:49 - 2017-10-04 05:04 - 001570304 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-11-15 10:49 - 2017-10-04 05:04 - 000670208 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-11-15 10:49 - 2017-10-04 05:04 - 000603648 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-11-15 10:49 - 2017-10-04 05:04 - 000370688 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-11-15 10:49 - 2017-10-04 05:04 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-11-15 10:49 - 2017-10-04 05:04 - 000181760 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-11-15 10:23 - 2017-11-15 10:23 - 000000000 ____D C:\Users\Patrick\Documents\PassMark
2017-11-15 10:22 - 2017-11-15 10:22 - 000000952 _____ C:\Users\Patrick\Desktop\PerformanceTest.lnk
2017-11-15 10:22 - 2017-11-15 10:22 - 000000000 ____D C:\Users\Patrick\AppData\Local\PassMark
2017-11-15 10:22 - 2017-11-15 10:22 - 000000000 ____D C:\ProgramData\Passmark
2017-11-15 10:22 - 2017-11-15 10:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PerformanceTest
2017-11-15 10:22 - 2017-11-15 10:22 - 000000000 ____D C:\Program Files\PerformanceTest
2017-11-15 10:07 - 2017-11-15 10:07 - 000000000 ____D C:\Windows\System32\Tasks\Games
2017-11-14 12:19 - 2017-11-19 21:21 - 000064424 _____ C:\Users\Owner\AppData\Local\GDIPFONTCACHEV1.DAT
2017-11-14 12:07 - 2017-11-19 13:20 - 000000008 __RSH C:\Users\Patrick\ntuser.pol
2017-11-14 11:52 - 2017-11-14 11:52 - 000000000 ____D C:\Users\Owner\AppData\Roaming\Wipe
2017-11-14 11:35 - 2017-11-14 11:35 - 000000000 ____D C:\Users\Owner\AppData\Roaming\9-lab
2017-11-14 11:17 - 2017-11-14 11:17 - 000000207 _____ C:\Windows\
2017-11-14 10:26 - 2017-11-15 20:04 - 000000000 ____D C:\EEK
2017-11-14 09:13 - 2017-11-14 09:13 - 000000000 ____D C:\Users\Patrick\AppData\Local\ESET
2017-11-14 09:13 - 2017-11-14 09:13 - 000000000 ____D C:\Users\Owner\AppData\Local\ESET
2017-11-14 08:44 - 2017-11-21 17:22 - 000000000 ____D C:\Program Files\9-lab
2017-11-14 08:44 - 2017-11-14 11:37 - 000001095 _____ C:\Users\Public\Desktop\Removal Tool.lnk
2017-11-14 08:44 - 2017-11-14 08:44 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\9-lab
2017-11-14 08:44 - 2017-11-14 08:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
2017-11-14 08:44 - 2017-11-14 08:44 - 000000000 ____D C:\ProgramData\9-lab
2017-11-14 06:08 - 2017-11-14 06:58 - 000000000 ____D C:\Users\Patrick\Downloads\Andromeda
2017-11-13 17:59 - 2017-11-13 20:12 - 000000000 ____D C:\Users\Owner\Documents\The Dark Tower Complete Chronological Collection
2017-11-08 19:52 - 2017-11-08 19:52 - 000000000 ____D C:\ProgramData\Blizzard Entertainment
2017-11-08 11:06 - 2017-11-08 11:06 - 000365168 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-11-05 18:55 - 2017-11-05 18:55 - 000000000 ____D C:\Users\Owner\AppData\Roaming\OpenOffice
2017-11-05 18:53 - 2017-11-05 20:10 - 000000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.4
2017-11-05 18:53 - 2017-11-05 18:53 - 000001112 _____ C:\Users\Public\Desktop\OpenOffice 4.1.4.lnk
2017-11-05 18:53 - 2017-11-05 18:53 - 000000000 ____D C:\Program Files (x86)\OpenOffice 4
2017-11-04 17:45 - 2017-11-04 17:45 - 000000000 ____D C:\Users\Patrick\Documents\Diablo II
2017-11-04 09:54 - 2017-11-21 14:51 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2017-11-04 09:50 - 2017-11-14 12:07 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2017-11-04 09:49 - 2017-11-04 10:29 - 000001945 _____ C:\Users\Owner\Desktop\Diablo II - Lord of Destruction.lnk
2017-11-04 09:49 - 2017-11-04 09:49 - 000001905 _____ C:\Users\Patrick\Desktop\Diablo II - Lord of Destruction.lnk
2017-11-04 09:49 - 2017-11-04 09:49 - 000001905 _____ C:\Users\Administrator\Desktop\Diablo II - Lord of Destruction.lnk
2017-11-04 09:49 - 2017-11-04 09:49 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Diablo II
2017-11-04 09:45 - 2017-11-05 19:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II
2017-11-04 09:45 - 2017-11-04 17:45 - 000038851 _____ C:\Windows\DIIUnin.dat
2017-11-04 09:45 - 2017-11-04 09:45 - 000094208 _____ (Blizzard Entertainment) C:\Windows\DIIUnin.exe
2017-11-04 09:45 - 2017-11-04 09:45 - 000002829 _____ C:\Windows\DIIUnin.pif
2017-11-04 09:43 - 2017-11-04 17:45 - 000000000 ____D C:\Program Files (x86)\Diablo II
2017-11-04 09:36 - 2017-11-04 09:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2017-11-04 09:36 - 2017-11-04 09:36 - 000000000 ____D C:\Program Files (x86)\Elaborate Bytes
2017-10-31 06:41 - 2017-11-17 16:30 - 000000000 ____D C:\Users\Owner\dwhelper
2017-10-31 06:29 - 2017-11-21 14:12 - 000000000 ____D C:\Users\Owner\Documents\Computer Diagnostics Tools
2017-10-31 06:04 - 2017-11-03 07:35 - 000183584 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2017-10-26 12:01 - 2017-10-26 12:01 - 000010552 ____N C:\bootsqm.dat
2017-10-26 11:57 - 2017-10-26 11:57 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\AVAST Software
2017-10-26 11:54 - 2017-10-26 11:54 - 000058016 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2017-10-26 11:53 - 2017-10-26 11:53 - 000000000 ____D C:\Users\Administrator\AppData\Local\Zemana
2017-10-26 11:51 - 2017-10-26 11:51 - 000001413 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-10-26 11:51 - 2017-10-26 11:51 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Adobe
2017-10-26 11:48 - 2017-11-21 14:01 - 000000000 ____D C:\Users\Administrator
2017-10-26 11:48 - 2017-10-26 11:48 - 000000020 ___SH C:\Users\Administrator\ntuser.ini
2017-10-26 11:48 - 2011-04-12 00:28 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Media Center Programs
2017-10-26 11:03 - 2017-10-26 11:03 - 000000000 ___HD C:\VTRoot
2017-10-26 11:02 - 2017-11-20 18:33 - 000057854 _____ C:\Windows\system32\Drivers\fvstore.dat
2017-10-26 09:52 - 2017-10-26 09:52 - 000000000 ____D C:\$AV_ASW
2017-10-26 08:24 - 2017-11-17 09:52 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-10-25 15:10 - 2017-11-16 10:14 - 000000000 ____D C:\Program Files (x86)\SpeedFan
2017-10-25 15:10 - 2017-10-25 15:12 - 000001011 _____ C:\Users\Patrick\Desktop\SpeedFan.lnk
2017-10-25 15:10 - 2017-10-25 15:12 - 000000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2017-10-25 15:10 - 2017-10-25 15:10 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan
2017-10-24 17:47 - 2017-09-07 05:05 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-10-24 17:47 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-10-23 08:41 - 2017-10-24 14:00 - 000000000 ____D C:\Windows\Minidump
2017-10-22 11:56 - 2017-10-22 11:56 - 000000000 ____D C:\Users\Owner\AppData\Local\GyroscopeGames
2017-10-22 08:57 - 2017-10-22 08:57 - 000000000 ____D C:\Users\Owner\Desktop\PrivaZer registry backups
2017-10-22 08:26 - 2017-10-22 08:26 - 000000000 ____D C:\ProgramData\Dell
2017-10-22 08:23 - 2017-11-21 17:26 - 000000000 ____D C:\Users\Owner\AppData\Local\Deployment
2017-10-22 08:23 - 2017-10-22 08:23 - 000000000 ____D C:\Users\Owner\AppData\Local\Apps\2.0

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-21 17:33 - 2017-10-06 07:55 - 000000000 ____D C:\Users\Owner\AppData\LocalLow\Mozilla
2017-11-21 17:28 - 2017-10-05 17:01 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2017-11-21 17:28 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-11-21 17:21 - 2017-10-06 07:40 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\Mozilla
2017-11-21 17:19 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\inf
2017-11-21 14:51 - 2017-10-13 10:12 - 000115800 _____ C:\Windows\ZAM.krnl.trace
2017-11-21 14:51 - 2017-10-13 10:12 - 000065712 _____ C:\Windows\ZAM_Guard.krnl.trace
2017-11-21 14:51 - 2017-10-05 17:01 - 000000000 ____D C:\ProgramData\HitmanPro.Alert
2017-11-21 14:51 - 2009-07-13 20:45 - 000029120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-21 14:51 - 2009-07-13 20:45 - 000029120 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-21 13:45 - 2017-10-06 15:55 - 000029168 _____ C:\Users\Owner\Desktop\PrivaZer.ini
2017-11-21 13:38 - 2017-10-06 07:49 - 000000000 ____D C:\Program Files (x86)\System Ninja
2017-11-21 13:33 - 2017-10-05 20:59 - 000000000 ____D C:\Users\Owner\Documents\Calibre Library
2017-11-21 13:30 - 2017-10-04 13:57 - 000000000 ____D C:\Users\Patrick
2017-11-21 13:25 - 2017-10-05 19:20 - 000000000 ____D C:\Users\Owner\AppData\Roaming\vlc
2017-11-21 11:08 - 2017-10-05 16:52 - 000004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-11-20 21:27 - 2009-07-13 21:13 - 000778180 _____ C:\Windows\system32\PerfStringBackup.INI
2017-11-20 19:05 - 2017-10-07 15:05 - 000000000 ____D C:\Users\Patrick\AppData\Roaming\Wipe
2017-11-20 13:36 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\Web
2017-11-20 13:08 - 2017-10-11 22:03 - 000000000 ____D C:\ProgramData\TEMP
2017-11-19 22:32 - 2017-10-06 13:06 - 000278914 __RSH C:\Users\Owner\ntuser.pol
2017-11-19 22:32 - 2017-10-05 18:16 - 000000000 ____D C:\Users\Owner
2017-11-19 21:10 - 2017-10-04 16:05 - 000778180 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-11-19 21:10 - 2009-07-13 18:34 - 000000873 _____ C:\Windows\win.ini
2017-11-19 15:00 - 2017-10-05 17:40 - 000000000 ____D C:\Program Files\PeerBlock
2017-11-19 14:42 - 2017-10-05 19:17 - 000000000 ____D C:\Users\Owner\AppData\Roaming\uTorrent
2017-11-19 12:40 - 2017-10-06 07:30 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-11-19 12:08 - 2017-10-14 09:46 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-11-18 16:32 - 2009-07-13 19:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2017-11-18 16:03 - 2009-07-13 18:34 - 000000215 _____ C:\Windows\system.ini
2017-11-18 15:54 - 2017-10-21 10:56 - 000000000 ____D C:\Windows\erdnt
2017-11-17 12:44 - 2009-07-13 21:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-11-17 12:34 - 2017-10-17 20:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
2017-11-17 12:27 - 2017-10-17 20:00 - 000000000 ____D C:\GOG Games
2017-11-16 18:33 - 2017-10-06 07:55 - 000000000 ____D C:\Users\Owner\AppData\Roaming\Mozilla
2017-11-16 13:48 - 2017-10-13 15:28 - 000000000 ____D C:\Users\Owner\Documents\Windows 7 Legal Isos
2017-11-16 12:49 - 2017-10-14 11:57 - 000000000 ____D C:\ProgramData\HitmanPro
2017-11-15 14:49 - 2017-10-07 15:05 - 000000000 ____D C:\Program Files\Wipe
2017-11-15 11:39 - 2009-07-13 19:20 - 000000000 __RHD C:\Users\Public\Libraries
2017-11-15 11:31 - 2017-10-05 10:07 - 000000000 ____D C:\Windows\system32\appraiser
2017-11-15 10:01 - 2017-10-05 16:52 - 000455376 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-11-14 21:16 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\tracing
2017-11-14 12:01 - 2011-04-12 00:28 - 000000000 ___RD C:\Users\Public\Recorded TV
2017-11-14 10:22 - 2017-10-06 09:00 - 000028460 _____ C:\Users\Patrick\Desktop\PrivaZer.ini
2017-11-10 17:06 - 2017-10-05 20:59 - 000000930 _____ C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk
2017-11-10 17:06 - 2017-10-05 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2017-11-10 17:06 - 2017-10-05 20:58 - 000000000 ____D C:\Program Files\Calibre2
2017-11-07 12:54 - 2017-10-06 08:29 - 000000000 ____D C:\Users\Owner\Documents\Religious Debates
2017-11-05 20:10 - 2017-10-05 17:01 - 000000000 ____D C:\ProgramData\Unchecky
2017-11-04 09:53 - 2017-10-10 11:07 - 000000000 ____D C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2017-11-03 07:35 - 2017-10-05 16:52 - 001026232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-11-03 07:35 - 2017-10-05 16:52 - 000364464 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-11-03 07:35 - 2017-10-05 16:52 - 000203976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-11-03 07:35 - 2017-10-05 16:52 - 000148288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-11-03 07:35 - 2017-10-05 16:52 - 000110376 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-11-03 07:35 - 2017-10-05 16:52 - 000084416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-11-03 07:35 - 2017-10-05 16:52 - 000047008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-10-31 06:03 - 2017-10-05 16:52 - 000343288 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-10-31 06:03 - 2017-10-05 16:52 - 000321032 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-10-31 06:03 - 2017-10-05 16:52 - 000198968 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-10-31 06:03 - 2017-10-05 16:52 - 000057728 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-10-26 12:02 - 2009-07-13 21:08 - 000032638 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-10-26 11:52 - 2009-07-13 20:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-10-26 11:15 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\Registration
2017-10-26 08:24 - 2017-10-06 07:30 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-10-26 08:24 - 2017-10-06 07:30 - 000000854 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-10-26 03:47 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\rescache
2017-10-25 17:40 - 2017-10-05 22:30 - 000000000 ____D C:\Users\Owner\AppData\Local\gtk-2.0

==================== Files in the root of some directories =======

2017-11-21 17:19 - 2017-08-29 04:52 - 004784832 _____ (COMODO) C:\ProgramData\cis7D3A.exe
2017-11-21 17:19 - 2017-08-29 04:56 - 000365248 _____ (COMODO) C:\ProgramData\cmdres.dll
2017-11-21 13:40 - 2017-11-21 13:40 - 000000344 _____ () C:\Users\Patrick\AppData\Local\000ClearPageFileAtShutdown
2017-11-19 13:25 - 2017-11-19 13:25 - 000000637 _____ () C:\Users\Patrick\AppData\Local\ZHPFixReport.txt

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-20 19:29

==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-11-2017
Ran by Patrick (21-11-2017 17:36:03)
Running from C:\Users\Owner\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2017-10-04 21:57:30)
Boot Mode: Normal

==================== Accounts: =============================

Administrator (S-1-5-21-1492466166-1735938548-1690570200-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-1492466166-1735938548-1690570200-501 - Limited - Disabled)
Owner (S-1-5-21-1492466166-1735938548-1690570200-1001 - Limited - Enabled) => C:\Users\Owner
Patrick (S-1-5-21-1492466166-1735938548-1690570200-1000 - Administrator - Enabled) => C:\Users\Patrick

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\uTorrent) (Version: - BitTorrent Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.8.2318 - AVAST Software)
calibre 64bit (HKLM\...\{3E7334AB-3B64-4CD0-8DAC-817FF56AED7E}) (Version: 3.12.0 - Kovid Goyal)
CDisplay 1.8 (HKLM-x32\...\CDisplay_is1) (Version: - dvd8n)
Diablo II (HKLM-x32\...\Diablo II) (Version: - )
Freedome (HKLM-x32\...\F-Secure Freedome) (Version: 1.20.3671.0 - F-Secure Corporation)
Geeks3D FurMark (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: - Google Inc.) Hidden
HostsMan 4.7.105 (HKLM-x32\...\{1A3DD1A9-7B7B-4ECA-AD2F-98466F49F62C}_is1) (Version: -
Imperium Galactica II - Alliances (HKLM-x32\...\1254614904_is1) (Version: -
Intel(R) Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mozilla Firefox 57.0 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0 (x64 en-US)) (Version: 57.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 56.0.2 - Mozilla)
MSI Afterburner 4.4.0 (HKLM-x32\...\Afterburner) (Version: 4.4.0 - MSI Co., LTD)
OpenOffice 4.1.4 (HKLM-x32\...\{4138A847-021B-4C26-B6BF-220B2446F603}) (Version: 4.14.9787 - Apache Software Foundation)
PeerBlock 1.2 (r693) (HKLM\...\{015C5B35-B678-451C-9AEE-821E8D69621C}_is1) (Version: - PeerBlock, LLC)
PerformanceTest v9.0 (HKLM\...\PerformanceTest 9_is1) (Version: 9.0.1020.0 - Passmark Software)
RivaTuner Statistics Server 7.0.0 (HKLM-x32\...\RTSS) (Version: 7.0.0 - Unwinder)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
STAR WARS® - Knights of the Old Republic™ (HKLM-x32\...\1207666283_is1) (Version: -
System Ninja version 3.1.5 (HKLM-x32\...\{6E67710E-206D-43AB-BF21-E7CD63056C55}_is1) (Version: 3.1.5 - SingularLabs)
Unchecky v1.1 (HKLM-x32\...\Unchecky) (Version: 1.1 - Reason Software Company Inc.)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: - Elaborate Bytes)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
Wipe (HKLM\...\wipe) (Version: 17.16 -

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-08] (AVAST Software)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-08] (AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-08] (AVAST Software)
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-08] (AVAST Software)
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2012-11-14] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-08] (AVAST Software)
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-11] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {2F74E8B2-69A2-4A0F-A3E5-9EBDFD44AD0D} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: {8718438F-026F-4EED-BD40-41BDE9C337CB} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-11-08] (AVAST Software)
Task: {9514F30D-C8DA-4CB1-AB27-D743DD03904E} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
Task: {A432B3CF-C559-407B-9656-D8E9A2E12DBF} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1492466166-1735938548-1690570200-1000
Task: {AE5F3DE8-C9FB-47B7-AE5A-8B5B3259C90D} - System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: {EA935066-368B-4288-92AE-C3C9403B8386} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}.job => C:\ProgramData\cis7D3A.exe <==== ATTENTION

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2017-11-08 11:06 - 2017-11-08 11:06 - 000067408 _____ () C:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll
2017-11-08 11:05 - 2017-11-08 11:05 - 000169832 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll
2017-11-08 11:06 - 2017-11-08 11:06 - 000859216 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll
2017-11-08 11:06 - 2017-11-08 11:06 - 000292408 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll
2017-11-08 11:06 - 2017-11-08 11:06 - 000059040 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll
2017-11-08 11:06 - 2017-11-08 11:06 - 000167096 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-11-08 11:06 - 2017-11-08 11:06 - 000237808 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-11-08 11:06 - 2017-11-08 11:06 - 000244584 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-11-08 11:06 - 2017-11-08 11:06 - 000151104 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll
2017-11-21 11:12 - 2017-11-21 11:12 - 005849360 _____ () C:\Program Files\AVAST Software\Avast\defs\17112104\algo.dll
2017-11-08 11:06 - 2017-11-08 11:06 - 000710056 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-10-05 16:52 - 2017-10-05 16:52 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-11-08 11:05 - 2017-11-08 11:05 - 000235816 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-10-05 17:35 - 2017-10-05 17:35 - 000157152 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\lzo2.dll
2017-10-05 17:35 - 2017-10-05 17:35 - 000075232 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\libpkcs11-helper-1.dll
2017-10-05 17:36 - 2017-10-05 17:36 - 000698848 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\QtQuick\Controls\qtquickcontrolsplugin.dll
2017-10-05 17:35 - 2017-10-05 17:35 - 000019424 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\libEGL.dll
2017-10-05 17:35 - 2017-10-05 17:35 - 001610720 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\libGLESv2.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP😀1B5B4F1 [151]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\camsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dps => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\lfsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SamSs => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\semgrsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\shellhwdetection => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srv2 => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\srvnet => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TokenBroker => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TweakingRemoveSafeBoot => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1492466166-1735938548-1690570200-1000\...\ ->
IE trusted site: HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\ ->

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-11-19 11:20 - 2017-11-21 17:29 - 031597874 __RSH C:\Windows\system32\Drivers\etc\hosts localhost

There are 919962 more lines.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1492466166-1735938548-1690570200-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
DNS Servers:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
mpsdrv => Firewall Service is not running.
MpsSvc => Firewall Service is not running.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: PCToolsSSDMonitorSvc => 2
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\Services: VoodooShieldService => 2
MSCONFIG\startupreg: uTorrent => "C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: Wipe Maintance => "C:\Program Files\Wipe\net1.exe" windowsStartup

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{8EA77410-6200-4326-96A9-2DC1FC8F8723}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{02D1563B-D869-4314-A7CF-3BFE79A9F8C0}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{E37B2E3D-BD7E-4D14-9C50-96028AAF46AD}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C8253294-4436-430C-B5EE-91193083C298}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C36A565E-B5A0-48B3-8973-F3559B6166A0}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{81CC9780-9D96-4C73-8ED4-A01A4676623F}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{F48882C1-0AD6-4DDD-A9C0-E213A7D9827A}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{54F0A311-72F9-49BD-8D81-291074F5556B}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{307BF65A-9757-43AB-858C-3B68ABB3E2A6}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{DF6A0D1D-5D57-4D6C-96B6-104AFBA3A8B2}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{24132901-D7BA-4A97-91FA-E60B7D31FB47}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{60E6D465-398E-4850-BE86-7EF7620A2377}] => (Block) C:\windows\system32\svchost.exe

==================== Restore Points =========================

21-11-2017 12:31:10 Scheduled Checkpoint
Check "winmgmt" service or repair WMI.

==================== Faulty Device Manager Devices =============

Name: ZAM Helper Driver
Description: ZAM Helper Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Service: ZAM
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: ZAM Guard Driver
Description: ZAM Guard Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Service: ZAM_Guard
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

==================== Event log errors: =========================

Application errors:
Error: (11/21/2017 05:18:38 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Windows\Installer\MSIC7F5.tmp -rptype 1 -descr "Removing COMODO Client - Security" -logfile "C:\Users\Patrick\AppData\Local\Temp\COMODO Internet Security dbgout.log" -working; Description = Removing COMODO Client - Security; Error = 0x8007043c).

Error: (11/21/2017 01:38:46 PM) (Source: ESENT) (EventID: 454) (User: )
Description: DllHost (2980) WebCacheLocal: Database recovery/restore failed with unexpected error -543.

Error: (11/21/2017 01:38:46 PM) (Source: ESENT) (EventID: 452) (User: )
Description: DllHost (2980) WebCacheLocal: Database C:\Users\Patrick\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat requires logfiles 43-58 in order to recover successfully. Recovery could only locate logfiles starting at 58.

Error: (11/20/2017 08:57:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: hmpalert.exe, version:, time stamp: 0x59498821
Faulting module name: ntdll.dll, version: 6.1.7601.23915, time stamp: 0x59b94a16
Exception code: 0xc000000d
Fault offset: 0x00097e41
Faulting process id: 0x364
Faulting application start time: 0x01d362715e166371
Faulting application path: C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: 8648435f-ce78-11e7-ac61-00256460faa9

System errors:
Error: (11/21/2017 05:29:27 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:

Error: (11/21/2017 05:29:09 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Windows Image Acquisition (WIA) service depends on the Shell Hardware Detection service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Error: (11/21/2017 05:19:21 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server:

Error: (11/21/2017 05:18:53 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (11/21/2017 05:18:38 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1084" attempting to start the service cmdAgent with arguments "" in order to run the server:

Error: (11/21/2017 05:18:31 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server:

Error: (11/21/2017 05:17:40 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (11/21/2017 05:17:40 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (11/21/2017 05:17:40 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
The dependency service or group failed to start.

Error: (11/21/2017 05:17:40 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
The dependency service or group failed to start.

Date: 2017-11-21 14:22:18.078
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-21 14:22:17.938
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-21 13:49:33.118
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-21 13:49:33.009
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-21 11:04:34.635
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-21 11:04:34.526
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-20 21:33:01.863
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-20 21:33:01.723
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-20 21:22:07.625
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

Date: 2017-11-20 21:22:07.516
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\api-ms-win-core-synch-l1-2-0.dll because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz
Percentage of memory in use: 35%
Total physical RAM: 4056.36 MB
Available physical RAM: 2635.39 MB
Total Virtual: 8110.91 MB
Available Virtual: 6763.56 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:360.96 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: B5DFBF56)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================
For the record the errors I was having that led me to post initially, I'm still having even after uninstalling the programs.
hello PatL,

Please left click on the attached Fixlist.txt file at the bottom of this post. On the dialogue box that opens click "Save File" and then "OK"


Select a location then save the file. IMPORTANT the fixlist.txt file must be in the same location as the FRST program otherwise the fix will not work.


To run the fix right click the FRST icon and choose "Run as Administrator" then click on "Fix"


Depending on the amount of data to be moved it may take a few minutes to complete, and the computer may reboot. When the fix is complete and/or the computer has rebooted the "Fixlist.txt" file you created will be renamed "Fixlog.txt"

Please COPY and PASTE the contents of this new file in your next post🙂

After you have performed the FRST fix then please also provide a logfile from ZHP.

Please go HERE and click the

link (French for Download) and save it to your desktop.

Once saved to your desktop left click the new icon
and choose "Run as administrator"

Accept any security warnings that may pop up.

Then select
  1. Options
  2. Check all
  3. Validate
  4. Close

Next select Scanner from the main interface.


Depending on the amount of data on your PC it may take a little time to complete. Once it finishes then click the Report tab as shown above and a notepad file will open with your report file.

Please COPY and PASTE the contents of the notepad file with your next post🙂


Okay Gus the VPN is working again and still has all my info so I didn't lose it! 🙂 Now that that is corrected, should I remove the F-Secure/Freedome entries and re-run the first fixlist or do you want to rewrite it differently?
Here is the ZHPDiag report

~ ZHPDiag v2017.11.16.200 By Nicolas Coolman (2017/11/16)
~ Run by Patrick (Administrator) (2017/11/24 13:06:20)
~ Web:
~ Blog:
~ Facebook:
~ Certificate ZHPDiag: Legal
~ State version:
~ Mode: Scan
~ Report: C:\Users\Patrick\Desktop\ZHPDiag.txt
~ Report: C:\Users\Patrick\AppData\Roaming\ZHP\ZHPDiag.txt
~ UAC: Activate
~ System startup: Normal (Normal boot)
Windows 7 Home Premium, 64-bit Service Pack 1 (Build 7601) =>.Microsoft Corporation

---\\ Internet Browsers (3) - 0s
~ GCIE: Google Chrome v61.0.3163.100
~ MFIE: Mozilla Firefox 57.0 (x64 en-US)
~ MSIE: Internet Explorer v11.0.9600.18837

---\\ Windows Product Information (4) - 0s
~ Windows Server License Manager Script : OK
~ Licence Script File Génération : OK
Windows Automatic Updates : OK
Windows Activation Technologies : KO

---\\ System protection software (1) - 1s
Avast Free Antivirus v17.9.2319 (Protection)

---\\ Information on the system (6) - 0s
~ Operating System: Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
~ Operating System: 64-bit
~ Boot mode: Normal (Normal boot)
Total RAM: 4153.716 MB (63% free) : OK =>.RAM Value
System Restore: Activé (Enable)
System drive has 364 GB (76%) free of 476 GB : OK =>.Disk Space

---\\ Connection to the system mode (3) - 0s
~ Computer Name: PATRICK-PC
~ User Name: Patrick
~ Logged in as Administrator

---\\ Enumeration of the disk units (2) - 0s
~ Drive C: has 364 GB free of 476 GB
~ Drive E: has GB free of 0 GB

---\\ State of the Windows Security Center (14) - 0s
[HKLM\Software\WOW6432Node\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] WarnOnHTTPSToHTTPRedirect: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK
[HKLM64\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK
[HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install] LastSuccessTime : OK

---\\ Search Generic System Files (24) - 1s
[MD5.38AE1B3C38FAEF56FE4907922F0385BA] - 18/07/2017 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [3229696] =>.Microsoft Corporation
[MD5.C36BB659F08F046B139C8D1B980BF1AC] - 18/07/2017 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [46080] =>.Microsoft Corporation
[MD5.94355C28C1970635A31B3FE52EB7CEBA] - 18/07/2017 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [129024] =>.Microsoft Corporation
[MD5.D13A0397ED940C071FD5ABB76BC974CF] - 18/07/2017 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [3241472] =>.Microsoft Corporation
[MD5.8CEBD9D0A0A879CDE9F36F4383B7CAEA] - 18/07/2017 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [455168] =>.Microsoft Corporation
[MD5.067FA52BFB59A56110A12312EF9AF243] - 18/07/2017 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [232448] =>.Microsoft Corporation
[MD5.492D07D79E7024CA310867B526D9636D] - 18/07/2017 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [357888] =>.Microsoft Corporation
[MD5.B40420876B9288E0A1C8CCA8A84E5DC9] - 18/07/2017 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [270336] =>.Microsoft Corporation
[MD5.0DC2A9882540DEA4A55B08785E09D8FC] - 18/07/2017 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [496128] =>.Microsoft Corporation
[MD5.02062C0B390B7729EDC9E69C680A6F3C] - 18/07/2017 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [24128] =>.Microsoft Windows®
[MD5.B8BD2BB284668C84865658C77574381A] - 18/07/2017 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation
[MD5.F036CE71586E93D94DAB220D7BDF4416] - 18/07/2017 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [147456] =>.Microsoft Corporation
[MD5.9B38580063D281A99E68EF5813022A5F] - 18/07/2017 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [106496] =>.Microsoft Corporation
[MD5.97BFED39B6B79EB12CDDBFEED51F56BB] - 18/07/2017 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [122368] =>.Microsoft Corporation
[MD5.FA55C73D4AFFA7EE23AC4BE53B4592D3] - 18/07/2017 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [105472] =>.Microsoft Corporation
[MD5.AF9B39A7E7B6CAA203B3862582E9F2D0] - 18/07/2017 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [116224] =>.Microsoft Corporation
[MD5.767C6DF04C5758B9F0790D400541B44F] - 18/07/2017 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [159744] =>.Microsoft Corporation
[MD5.734837208CAFD6E0959A7A0333C95C9D] - 18/07/2017 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [262656] =>.Microsoft Corporation
[MD5.1065D9AFE491706EB00AD3CBB76C9E54] - 18/07/2017 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [1680616] {330000004B76632D24A2399A8B00010000004B} =>.Microsoft Corporation
[MD5.0086431C29C35BE1DBC43F52CC273887] - 18/07/2017 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [97280] =>.Microsoft Corporation
[MD5.471815800AE33E6F1C32FB1B97C490CA] - 18/07/2017 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [129536] =>.Microsoft Corporation
[MD5.548260A7B8654E024DC30BF8A7C5BAA4] - 18/07/2017 - (.Microsoft Corporation - SMB Transport driver.) -- C:\Windows\System32\drivers\smb.sys [93184] =>.Microsoft Corporation
[MD5.4DD986720F7CB7A8A5D1226793097B9A] - 18/07/2017 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [117248] =>.Microsoft Corporation
[MD5.0D08D2F3B3FF84E433346669B5E0F639] - 18/07/2017 - (.Microsoft Corporation - Volume Shadow Copy Driver.) -- C:\Windows\System32\drivers\volsnap.sys [295808] =>.Microsoft Windows®

---\\ Non Microsoft non disabled Windows Services (4) - 2s
O23 - Service: (AppMgmt) . (...) - C:\Windows\System32\appmgmts.dll (.not file.)
O23 - Service: Avast Antivirus (avast! Antivirus) . (.AVAST Software - Avast Service.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe =>.AVAST Software s.r.o.®
O23 - Service: F-Secure Freedome Service (Freedome Service) . (.F-Secure Corporation - F-Secure Freedome Service.) - C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\FreedomeService.exe =>.F-Secure Corporation®
O23 - Service: unchecky (Unchecky) . (.Reason Software Company Inc. - Unchecky Service.) - C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe =>.Reason Software Company Inc.®

---\\ Services not Microsoft (SR=Run, SS=Stop) (8) - 26s
SR - Demand [18/07/2017] [ 317408] aswbIDSAgent (aswbIDSAgent) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe =>.AVAST Software s.r.o.®
SR - Auto [18/07/2017] [ 317408] Avast Antivirus (avast! Antivirus) . (.AVAST Software.) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe =>.AVAST Software s.r.o.®
SR - Auto [18/07/2017] [ 317408] F-Secure Freedome Service (Freedome Service) . (.F-Secure Corporation.) - C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\FreedomeService.exe =>.F-Secure Corporation®
SS - Disabl [18/07/2017] [ 317408] Google Update Service (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Disabl [18/07/2017] [ 317408] Google Update Service (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc®
SS - Disabl [18/07/2017] [ 317408] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation®
SS - Disabl [18/07/2017] [ 317408] Skype Updater (SkypeUpdate) . (.Skype Technologies.) - C:\Program Files (x86)\Skype\Updater\Updater.exe =>.Skype Software Sarl®
SR - Auto [18/07/2017] [ 317408] unchecky (Unchecky) . (.Reason Software Company Inc..) - C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe =>.Reason Software Company Inc.®

---\\ Task Planned Automatically (Register) (49) - 6s
O38 - TASK: {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC} [64Bits][\Microsoft\Windows\Time Synchronization\SynchronizeTime] - (.Microsoft Corporation - A tool to aid in developing services for Wi.) -- C:\Windows\system32\sc.exe [45056] =>.Microsoft Corporation
O38 - TASK: {09D8D505-2562-4BBE-92BB-F6A11A840706} [64Bits][\Microsoft\Windows\Media Center\ActivateWindowsSearch] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {118CF4C5-C01C-4E41-B373-8C99C1760BA8} [64Bits][\Microsoft\Windows\Media Center\RegisterSearch] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {1504036E-3D2B-49E9-9F45-BF71227214A6} [64Bits][\Microsoft\Windows\Media Center\SqlLiteRecoveryTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- C:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {1C153F09-0A71-462C-A322-4B574FC8A1F2} [64Bits][\Microsoft\Windows\Media Center\OCURActivate] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} [64Bits][\Microsoft\Windows\WindowsBackup\ConfigNotification] - (.Microsoft Corporation - Microsoft® Windows Backup.) -- C:\Windows\System32\sdclt.exe [1264640] =>.Microsoft Corporation
O38 - TASK: {2F74E8B2-69A2-4A0F-A3E5-9EBDFD44AD0D} [64Bits][\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {37DE0797-D536-4228-8EA0-E74F3CA299D5} [64Bits][\Microsoft\Windows\Media Center\ehDRMInit] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {397159F3-DED0-4F4F-8242-D92BCF5C4440} [64Bits][\Microsoft\Windows\Application Experience\ProgramDataUpdater] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\Windows\system32\compattelrunner.exe [134376] {330000004B76632D24A2399A8B00010000004B} =>.Microsoft Corporation
O38 - TASK: {39A98B3C-C528-4993-8E16-3399E7A62867} [64Bits][\Microsoft\Windows\Media Center\mcupdate] - (...) -- C:\Windows\ehome\mcupdate (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {3B3DCCBA-789E-4662-A0AF-49E6D2F4BCF7} [64Bits][\Microsoft\Windows\Media Center\StartRecording] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {584647D8-9F21-4C53-8260-D04600C56165} [64Bits][\Avast Emergency Update] - (.AVAST Software - Avast Emergency Update.) -- C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2418624] =>.AVAST Software s.r.o.®
O38 - TASK: {5A40E926-9E86-4B89-9CFD-B12311724371} [64Bits][\Microsoft\Windows\UPnP\UPnPHostConfig] - (.Microsoft Corporation - A tool to aid in developing services for Wi.) -- \Windows\System32\sc.exe [45056] =>.Microsoft Corporation
O38 - TASK: {5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6} [64Bits][\Microsoft\Windows\Defrag\ScheduledDefrag] - (.Microsoft Corp. - Disk Defragmenter Module.) -- C:\Windows\system32\defrag.exe [183296] =>.Microsoft Corp.
O38 - TASK: {72DB7465-BC54-491B-A92A-4637A28C9BBF} [64Bits][\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck] - (.Microsoft Corporation - AppID Certificate Store Verification Task.) -- C:\Windows\system32\appidcertstorecheck.exe [17920] =>.Microsoft Corporation
O38 - TASK: {753C47AE-EC5E-44B3-95A9-2C8E553F0E39} [64Bits][\Microsoft\Windows\Windows Media Sharing\UpdateLibrary] - (.Microsoft Corporation - Windows Media Player Network Sharing Servic.) -- \Program Files\Windows Media Player\wmpnscfg.exe [70656] =>.Microsoft Corporation
O38 - TASK: {7A7263EF-BBD4-4055-8F45-260E31FCBF53} [64Bits][\Microsoft\Windows\Media Center\ConfigureInternetTimeService] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {856D7DA4-B730-4CB4-AAE8-DB980F91E202} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver] - (.Microsoft Corporation - Windows Disk Diagnostic User Resolver.) -- C:\Windows\system32\DFDWiz.exe [79360] =>.Microsoft Corporation
O38 - TASK: {9092047F-9B2A-4985-B7A0-FD3C51EA2844} [64Bits][\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector] - (.Microsoft Corporation - Windows Disk Failure Diagnostic Module.) -- \Windows\System32\dfdts.dll [45568] =>.Microsoft Corporation
O38 - TASK: {9281FDED-2D66-43D0-8E01-800B32E8F2C8} [64Bits][\Microsoft\Windows\Media Center\PBDADiscoveryW2] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {9447CEF0-83F4-4F9D-B4C1-D25DEC56F3D5} [64Bits][\Microsoft\Windows\Media Center\OCURDiscovery] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {9514F30D-C8DA-4CB1-AB27-D743DD03904E} [64Bits][\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {9576E959-7393-40F9-9915-4EE2A6FB11A0} [64Bits][\Microsoft\Windows\Media Center\DispatchRecoveryTasks] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {994C86AD-A929-4B2C-88A0-4E25A107A029} [64Bits][\Microsoft\Windows\SystemRestore\SR] - (.Microsoft Corporation - Microsoft® Windows System Protection Config.) -- \Windows\System32\srrstr.dll [270848] =>.Microsoft Corporation
O38 - TASK: {999DA5BD-5583-4F14-97FA-1602A926540D} [64Bits][\Microsoft\Windows\Media Center\RecordingRestart] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {9B594547-85FC-4A19-AF71-991DEE432F38} [64Bits][\Microsoft\Windows\Media Center\PBDADiscovery] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {9E18C653-A923-471E-B560-2F2C82B06B31} [64Bits][\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser] - (.Microsoft Corporation - Microsoft Compatibility Telemetry.) -- C:\Windows\system32\CompatTelRunner.exe [134376] {330000004B76632D24A2399A8B00010000004B} =>.Microsoft Corporation
O38 - TASK: {9FC63041-B748-48C3-B466-F626F61B6F2D} [64Bits][\Microsoft\Windows\Media Center\InstallPlayReady] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {A48CABBF-24C8-4B87-B00F-9261807C3B43} [64Bits][\Microsoft\Windows\AppID\PolicyConverter] - (.Microsoft Corporation - AppID Policy Converter Task.) -- C:\Windows\system32\appidpolicyconverter.exe [148480] =>.Microsoft Corporation
O38 - TASK: {A55EC790-32AF-4199-BC4A-235074276EB1} [64Bits][\Microsoft\Windows\Media Center\PvrRecoveryTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- C:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} [64Bits][\Microsoft\Windows\Location\Notifications] - (.Microsoft Corporation - Location Activity.) -- C:\Windows\System32\LocationNotifications.exe [90112] =>.Microsoft Corporation
O38 - TASK: {A7112BBA-E3E1-49DA-B48E-2E56FE0D0C86} [64Bits][\Microsoft\Windows\Media Center\UpdateRecordPath] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {AE5F3DE8-C9FB-47B7-AE5A-8B5B3259C90D} [64Bits][\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {BB7F8127-EFAC-4831-8429-1C93F4A877A8} [64Bits][\Microsoft\Windows\Media Center\PvrScheduleTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- C:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {C016366B-7126-46CA-B36B-592A3D95A60B} [64Bits][\Microsoft\Windows\Customer Experience Improvement Program\Consolidator] - (.Microsoft Corporation - Windows SQM Consolidator.) -- C:\Windows\System32\wsqmcons.exe [293888] =>.Microsoft Corporation
O38 - TASK: {C06483B9-0D7D-4FD0-B4FE-05F99C80A7CC} [64Bits][\Microsoft\Windows\Media Center\PBDADiscoveryW1] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {CA6B5B9B-034A-47AB-ABE7-6AFF06218E50} [64Bits][\Microsoft\Windows\Media Center\PeriodicScanRetry] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- C:\Windows\ehome\MCUpdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186} [64Bits][\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask] - (.Microsoft Corporation - Windows Remote Assistance COM Server.) -- C:\Windows\System32\raserver.exe [125952] =>.Microsoft Corporation
O38 - TASK: {CBE7A128-6154-4F7A-BD2D-A309959235BA} [64Bits][\Microsoft\Windows\Media Center\MediaCenterRecoveryTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- C:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation
O38 - TASK: {D0250F3F-6480-484F-B719-42F659AC64D5} [64Bits][\Microsoft\Windows\Windows Error Reporting\QueueReporting] - (.Microsoft Corporation - Windows Problem Reporting.) -- C:\Windows\system32\wermgr.exe [50688] =>.Microsoft Corporation
O38 - TASK: {D7B6E81D-3CF4-432C-84D2-24213F4316E6} [64Bits][\Microsoft\Windows\Autochk\Proxy] - (.Microsoft Corporation - Autochk Proxy DLL.) -- \Windows\System32\acproxy.dll [11264] =>.Microsoft Corporation
O38 - TASK: {DD9F510C-95F4-499A-90C8-BAC5BC372FF4} [64Bits][\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask] - (.Microsoft Corporation - A tool to aid in developing services for Wi.) -- \Windows\System32\sc.exe [45056] =>.Microsoft Corporation
O38 - TASK: {E22A8667-F75B-4BA9-BA46-067ED4429DE8} [64Bits][\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange] - (.Microsoft Corporation - Base Filtering Engine.) -- \Windows\System32\bfe.dll [705024] =>.Microsoft Corporation
O38 - TASK: {E3163C33-301D-4730-A266-5518C5ED3967} [64Bits][\Microsoft\Windows\Bluetooth\UninstallDeviceTask] - (.Microsoft Corporation - Bluetooth Uninstall Device Task.) -- \Windows\System32\BthUdTask.exe [36864] =>.Microsoft Corporation
O38 - TASK: {EA935066-368B-4288-92AE-C3C9403B8386} [64Bits][\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {EB02381F-D652-4B1C-894A-712498C62C51} [64Bits][\Microsoft\Windows\MUI\LPRemove] - (.Microsoft Corporation - MUI Language pack cleanup.) -- C:\Windows\system32\lpremove.exe [71168] =>.Microsoft Corporation
O38 - TASK: {F201E741-97DD-4F63-AAFB-93054BBF4B3A} [64Bits][\Microsoft\Windows\Media Center\ReindexSearchRoot] - (.Microsoft Corporation - Digital TV Tuner device registration applic.) -- C:\Windows\ehome\ehPrivJob.exe [295936] =>.Microsoft Corporation
O38 - TASK: {FB3C354D-297A-4EB2-9B58-090F6361906B} [64Bits][\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem] - (.Microsoft Corporation - Power Settings Command-Line Tool.) -- C:\Windows\System32\powercfg.exe [71168] =>.Microsoft Corporation
O38 - TASK: {FE66CC16-0C01-4464-A5D3-B6203D68FBE4} [64Bits][\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask] - (.Microsoft Corporation - Windows Media Center Store Update Manager.) -- C:\Windows\ehome\mcupdate.exe [198656] =>.Microsoft Corporation

---\\ Auto loading programs from Registry and folders (11) - 1s
O4 - HKLM\..\Run: [AvastUI.exe] . (.AVAST Software - AvLaunch component.) -- C:\Program Files\AVAST Software\Avast\AvLaunch.exe =>.AVAST Software s.r.o.®
O4 - HKLM\..\Run: [IgfxTray] . (.Intel Corporation - igfxTray Module.) -- C:\Windows\system32\igfxtray.exe =>.Intel Corporation
O4 - HKLM\..\Run: [Persistence] . (.Intel Corporation - persistence Module.) -- C:\Windows\system32\igfxpers.exe =>.Intel Corporation
O4 - HKLM\..\RunOnce: [000ClearPageFileAtShutdown] . (. - .) -- cmd
O4 - HKLM\..\RunOnce: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] . (.COMODO - COMODO Internet Security.) -- C:\ProgramData\cis7D3A.exe =>.Comodo Security Solutions, Inc.®
O4 - HKLM\..\RunOnce: [*Restore] . (.Microsoft Corporation - Microsoft® Windows System Restore.) -- C:\Windows\System32\rstrui.exe =>.Microsoft Corporation
O4 - HKCU\..\Run: [WinPatrol] . (.Ruiware - WinPatrol Monitor.) -- C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe =>.Ruiware, LLC®
O4 - HKCU\..\Run: [Wipe Maintance] . ( - Application Installer.) -- C:\Program Files\Wipe\net1.exe =>.Yury Saprykin®
O4 - HKLM\..\Wow6432Node\Run: [VirtualCloneDrive] . (.Elaborate Bytes AG - Virtual CloneDrive Daemon.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe =>.Elaborate Bytes AG®
O4 - HKUS\S-1-5-21-1492466166-1735938548-1690570200-1000\..\Run: [WinPatrol] . (.Ruiware - WinPatrol Monitor.) -- C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe =>.Ruiware, LLC®
O4 - HKUS\S-1-5-21-1492466166-1735938548-1690570200-1000\..\Run: [Wipe Maintance] . ( - Application Installer.) -- C:\Program Files\Wipe\net1.exe =>.Yury Saprykin®

---\\ Process running (12) - 1s
[MD5.34652C171663396C26E8C1E15A710B36] - (.AVAST Software - Avast Service.) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416] [PID.1276] =>.AVAST Software s.r.o.®
[MD5.EF714E87AB975A3B820E3295C73AD6EF] - (.F-Secure Corporation - F-Secure Freedome Service.) -- C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\FreedomeService.exe [592352] [PID.1688] =>.F-Secure Corporation®
[MD5.107AC0A12486F392A169763072A34C34] - (.Reason Software Company Inc. - Unchecky Service.) -- C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [294168] [PID.1940] =>.Reason Software Company Inc.®
[MD5.ED010E3C8B87B0910DD35D7883039621] - (.Reason Software Company Inc. - Unchecky Background Process.) -- C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe [612120] [PID.1996] =>.Reason Software Company Inc.®
[MD5.00000000000000000000000000000000] - (.Intel Corporation - persistence Module.) -- C:\Windows\System32\igfxpers.exe [0] [PID.1480] =>.Intel Corporation
[MD5.264FF661A5DA4211E85E55BCB0BF6D53] - (.Ruiware - WinPatrol Monitor.) -- C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe [1223560] [PID.1472] =>.Ruiware, LLC®
[MD5.DDF2CBFA4CF36ADD6C910F94D49EA2D2] - (.AVAST Software - Avast Antivirus.) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe [9238192] [PID.2164] =>.AVAST Software s.r.o.®
[MD5.3BD79A1F6D2EA0FDDEA3F8914B2A6A0C] - (.Elaborate Bytes AG - Virtual CloneDrive Daemon.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984] [PID.2268] =>.Elaborate Bytes AG®
[MD5.B6EA756B2FD8CCA5DD63F09A372C417F] - (.AVAST Software - Avast Behavior Shield.) -- C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7549928] [PID.2912] =>.AVAST Software s.r.o.®
[MD5.184937B23BE9ACD6AF88877ECC1A6DD9] - (.The OpenVPN Project - OpenVPN Daemon.) -- C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\openvpn.exe [662496] [PID.2440] =>.F-Secure Corporation®
[MD5.102F26366DC6B4A0F2868059CF5F05F2] - (.F-Secure Corporation - F-Secure Freedome UI.) -- C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\Freedome.exe [4338144] [PID.2516] =>.F-Secure Corporation®
[MD5.CFB11609FBBB1B1085F8BB2A25416C56] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\Owner\Desktop\ZHPDiag3.exe [2928512] [PID.2864] =>.Nicolas Coolman

---\\ Mozilla Firefox,Plugins,Start,Search,Extensions (5) - 4s
M0 - MFSP: prefs.js [Patrick - xxwz7xvm.default] =>.Google Inc.
P2 - EXT FILE: (.LanguageTool - Grammar and Style Check - __MSG_appDesc__.) -- C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default\extensions\
P2 - EXT FILE: (.uBlock Origin - __MSG_popupTipPicker__".) -- C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default\extensions\ =>.uBlock Origin
P2 - EXT FILE: (.Avast Online Security - Avast Browser Security and Web Reputat.) -- C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default\extensions\ =>.Avast Online Security
P2 - EXT FILE: (.Video DownloadHelper - Download Videos from the Web.) -- C:\Users\Patrick\AppData\Roaming\Mozilla\Firefox\Profiles\xxwz7xvm.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi =>.Video DownloadHelper

---\\ Internet Explorer Extensions, Start, Search (15) - 0s
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = =>.Microsoft Corporation
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = =>.Microsoft Corporation
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation
R3 - URLSearchHook: (no name)[HKCU] - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Browser.) (11.00.9600.18838 (winblue_ltsb.171013-1838)) -- C:\Windows\System32\ieframe.dll =>.Microsoft Corporation

---\\ Internet Explorer, Proxy Management (7) - 0s
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,EnableHttp1_1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyHttp1.1 = 1
R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigProxy = wininet.dll
R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] =>.Microsoft

---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s
F2 - REG:system.ini: UserInit=userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation
F2 - REG:system.ini: VMApplet=C:\Windows\SysWOW64\SystemPropertiesPerformance.exe (.Microsoft Corporation.) =>.Microsoft Corporation

---\\ Hosts file redirection (1) - 4s
~ Le fichier hôte est sain (The hosts file is clean) (923064)

---\\ Browser Helper Object (BHO) (1) - 0s
O2 - BHO: avast! Online Security [64Bits] - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll =>.AVAST Software s.r.o.®

---\\ Global shortcuts Startup (124) - 14s
O4 - GS\Desktop [Administrator]: CDisplay.lnk . (.David Ayton - Sequential Image Display (JPEG PNG & GIF).) C:\Program Files (x86)\CDisplay\CDisplay.exe
O4 - GS\Desktop [Administrator]: Diablo II - Lord of Destruction.lnk . (.Blizzard North - Diablo II.) C:\Program Files (x86)\Diablo II\Diablo II.exe =>.Blizzard North
O4 - GS\Desktop [Administrator]: FurMark.lnk . (.Geeks3D ( - FurMark - GPU stress test and OpenGL benchm.) C:\Program Files (x86)\Geeks3D\Benchmarks\FurMark\FurMark.exe =>.Geeks3D (
O4 - GS\Desktop [Administrator]: MSI Afterburner.lnk . (.Copyright © 2009-2017 Alexey Nicolaychuk aka Unwinder - MSIAfterburner.) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe {0E25850DA70F2EF8A7D9348F}
O4 - GS\Desktop [Administrator]: PeerBlock.lnk . (.PeerBlock, LLC - PeerBlock.) C:\Program Files\PeerBlock\peerblock.exe =>.PeerBlock, LLC®
O4 - GS\Desktop [Administrator]: PerformanceTest.lnk . (.PassMark Software - PerformanceTest Benchmark Software.) C:\Program Files\PerformanceTest\PerformanceTest64.exe =>.PassMark Software Pty Ltd®
O4 - GS\Desktop [Administrator]: SpeedFan.lnk . (...) C:\Program Files (x86)\SpeedFan\speedfan.exe =>.SOKNO S.R.L.®
O4 - GS\Desktop [Administrator]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Administrator]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\Patrick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Patrick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Administrator]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Administrator]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Administrator]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Administrator]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\TaskBar [Administrator]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Programs [Administrator]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Administrator]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Guest]: CDisplay.lnk . (.David Ayton - Sequential Image Display (JPEG PNG & GIF).) C:\Program Files (x86)\CDisplay\CDisplay.exe
O4 - GS\Desktop [Guest]: Diablo II - Lord of Destruction.lnk . (.Blizzard North - Diablo II.) C:\Program Files (x86)\Diablo II\Diablo II.exe =>.Blizzard North
O4 - GS\Desktop [Guest]: FurMark.lnk . (.Geeks3D ( - FurMark - GPU stress test and OpenGL benchm.) C:\Program Files (x86)\Geeks3D\Benchmarks\FurMark\FurMark.exe =>.Geeks3D (
O4 - GS\Desktop [Guest]: MSI Afterburner.lnk . (.Copyright © 2009-2017 Alexey Nicolaychuk aka Unwinder - MSIAfterburner.) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe {0E25850DA70F2EF8A7D9348F}
O4 - GS\Desktop [Guest]: PeerBlock.lnk . (.PeerBlock, LLC - PeerBlock.) C:\Program Files\PeerBlock\peerblock.exe =>.PeerBlock, LLC®
O4 - GS\Desktop [Guest]: PerformanceTest.lnk . (.PassMark Software - PerformanceTest Benchmark Software.) C:\Program Files\PerformanceTest\PerformanceTest64.exe =>.PassMark Software Pty Ltd®
O4 - GS\Desktop [Guest]: SpeedFan.lnk . (...) C:\Program Files (x86)\SpeedFan\speedfan.exe =>.SOKNO S.R.L.®
O4 - GS\Desktop [Guest]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Guest]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\Patrick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Patrick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Guest]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Guest]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Guest]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Guest]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\TaskBar [Guest]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Programs [Guest]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Guest]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Owner]: CDisplay.lnk . (.David Ayton - Sequential Image Display (JPEG PNG & GIF).) C:\Program Files (x86)\CDisplay\CDisplay.exe
O4 - GS\Desktop [Owner]: Diablo II - Lord of Destruction.lnk . (.Blizzard North - Diablo II.) C:\Program Files (x86)\Diablo II\Diablo II.exe =>.Blizzard North
O4 - GS\Desktop [Owner]: FurMark.lnk . (.Geeks3D ( - FurMark - GPU stress test and OpenGL benchm.) C:\Program Files (x86)\Geeks3D\Benchmarks\FurMark\FurMark.exe =>.Geeks3D (
O4 - GS\Desktop [Owner]: MSI Afterburner.lnk . (.Copyright © 2009-2017 Alexey Nicolaychuk aka Unwinder - MSIAfterburner.) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe {0E25850DA70F2EF8A7D9348F}
O4 - GS\Desktop [Owner]: PeerBlock.lnk . (.PeerBlock, LLC - PeerBlock.) C:\Program Files\PeerBlock\peerblock.exe =>.PeerBlock, LLC®
O4 - GS\Desktop [Owner]: PerformanceTest.lnk . (.PassMark Software - PerformanceTest Benchmark Software.) C:\Program Files\PerformanceTest\PerformanceTest64.exe =>.PassMark Software Pty Ltd®
O4 - GS\Desktop [Owner]: SpeedFan.lnk . (...) C:\Program Files (x86)\SpeedFan\speedfan.exe =>.SOKNO S.R.L.®
O4 - GS\Desktop [Owner]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Owner]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\Patrick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Owner]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Patrick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Owner]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Owner]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Owner]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Owner]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Owner]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Owner]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\TaskBar [Owner]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Programs [Owner]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Owner]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Patrick]: CDisplay.lnk . (.David Ayton - Sequential Image Display (JPEG PNG & GIF).) C:\Program Files (x86)\CDisplay\CDisplay.exe
O4 - GS\Desktop [Patrick]: Diablo II - Lord of Destruction.lnk . (.Blizzard North - Diablo II.) C:\Program Files (x86)\Diablo II\Diablo II.exe =>.Blizzard North
O4 - GS\Desktop [Patrick]: FurMark.lnk . (.Geeks3D ( - FurMark - GPU stress test and OpenGL benchm.) C:\Program Files (x86)\Geeks3D\Benchmarks\FurMark\FurMark.exe =>.Geeks3D (
O4 - GS\Desktop [Patrick]: MSI Afterburner.lnk . (.Copyright © 2009-2017 Alexey Nicolaychuk aka Unwinder - MSIAfterburner.) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe {0E25850DA70F2EF8A7D9348F}
O4 - GS\Desktop [Patrick]: PeerBlock.lnk . (.PeerBlock, LLC - PeerBlock.) C:\Program Files\PeerBlock\peerblock.exe =>.PeerBlock, LLC®
O4 - GS\Desktop [Patrick]: PerformanceTest.lnk . (.PassMark Software - PerformanceTest Benchmark Software.) C:\Program Files\PerformanceTest\PerformanceTest64.exe =>.PassMark Software Pty Ltd®
O4 - GS\Desktop [Patrick]: SpeedFan.lnk . (...) C:\Program Files (x86)\SpeedFan\speedfan.exe =>.SOKNO S.R.L.®
O4 - GS\Desktop [Patrick]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Desktop [Patrick]: ZHPCleaner.lnk . (.Nicolas Coolman - ZHPCleaner.) C:\Users\Patrick\AppData\Roaming\ZHP\ZHPCleaner.exe =>.Nicolas Coolman
O4 - GS\Desktop [Patrick]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\Patrick\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman
O4 - GS\Quicklaunch [Patrick]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\Quicklaunch [Patrick]: Launch Internet Explorer Browser.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\sendTo [Patrick]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation
O4 - GS\sendTo [Patrick]: Skype.lnk . (.Skype Technologies S.A. - Skype.) C:\Program Files (x86)\Skype\Phone\Skype.exe /sendto: =>.Skype Software Sarl®
O4 - GS\TaskBar [Patrick]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\TaskBar [Patrick]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\TaskBar [Patrick]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\Programs [Patrick]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Patrick]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\CommonDesktop [Public]: Avast Free Antivirus.lnk . (.AVAST Software - Avast Antivirus.) C:\Program Files\AVAST Software\Avast\AvastUI.exe =>.AVAST Software s.r.o.®
O4 - GS\CommonDesktop [Public]: calibre 64bit - E-book management.lnk . (...) C:\Program Files (x86)\Calibre2\calibre.exe
O4 - GS\CommonDesktop [Public]: Freedome.lnk . (.F-Secure Corporation - F-Secure Freedome UI.) C:\Program Files (x86)\F-Secure\Freedome\Freedome\1\Freedome.exe =>.F-Secure Corporation®
O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\CommonDesktop [Public]: Imperium Galactica II - Alliances.lnk . (...) C:\GOG Games\Imperium Galactica II\ig2.exe
O4 - GS\CommonDesktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\CommonDesktop [Public]: OpenOffice 4.1.4.lnk . (.Apache Software Foundation - OpenOffice 4.1.4.) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe =>.Apache Software Foundation
O4 - GS\CommonDesktop [Public]: Removal Tool.lnk . (...) C:\Program Files (x86)\9-lab\Removal Tool\rmtool.exe
O4 - GS\CommonDesktop [Public]: Star Wars - Knights of the Old Republic.lnk . (.BioWare Corp. - Star Wars: Knights of the Old Republic.) C:\GOG Games\Star Wars - KotOR\swkotor.exe =>.BioWare Corp.
O4 - GS\CommonDesktop [Public]: Unchecky.lnk . (.Reason Software Company Inc. - Unchecky.) C:\Program Files (x86)\Unchecky\unchecky.exe =>.Reason Software Company Inc.®
O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files\VideoLAN\VLC\vlc.exe =>.VideoLAN®
O4 - GS\Programs [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O4 - GS\Programs [Public]: Start Tor Browser.lnk . (.Mozilla Corporation - Tor Browser.) C:\Users\Patrick\Desktop\Tor Browser\Browser\firefox.exe =>.Mozilla Corporation
O4 - GS\Accessories [Public]: Command Prompt.lnk . (.Microsoft Corporation - Windows Command Processor.) C:\Windows\system32\cmd.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Windows Explorer.lnk . (.Microsoft Corporation - Windows Explorer.) C:\Windows\explorer.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Internet Explorer (No Add-ons).lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe -extoff =>.Microsoft Corporation®
O4 - GS\SystemTools [Public]: Private Character Editor.lnk . (.Microsoft Corporation - Private Character Editor.) C:\Windows\system32\eudcedit.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Calculator.lnk . (.Microsoft Corporation - Windows Calculator.) C:\Windows\system32\calc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: displayswitch.lnk . (.Microsoft Corporation - Display Switch.) C:\Windows\system32\displayswitch.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - Math Input Panel Accessory.) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Mobility Center.lnk . (.Microsoft Corporation - Windows Mobility Center.) C:\Windows\system32\mblctr.exe /open =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sound Recorder.lnk . (.Microsoft Corporation - Windows Sound Recorder.) C:\Windows\system32\SoundRecorder.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sticky Notes.lnk . (.Microsoft Corporation - Sticky Notes.) C:\Windows\system32\StikyNot.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Sync Center.lnk . (.Microsoft Corporation - Microsoft Sync Center.) C:\Windows\System32\mobsync.exe =>.Microsoft Corporation
O4 - GS\Accessories [Public]: Welcome Center.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\system32\rundll32.exe %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut =>..Microsoft Corporation
O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: dfrgui.lnk . (.Microsoft Corporation - Microsoft® Disk Defragmenter.) C:\Windows\system32\dfrgui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Disk Cleanup.lnk . (.Microsoft Corporation - Disk Space Cleanup Manager for Windows.) C:\Windows\system32\cleanmgr.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Resource Monitor.lnk . (.Microsoft Corporation - Resource and Performance Monitor.) C:\Windows\system32\perfmon.exe /res =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Information.lnk . (.Microsoft Corporation - System Information.) C:\Windows\system32\msinfo32.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: System Restore.lnk . (.Microsoft Corporation - Microsoft® Windows System Restore.) C:\Windows\system32\rstrui.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Task Scheduler.lnk . (...) C:\Windows\system32\taskschd.msc /s =>..Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer Reports.lnk . (.Microsoft Corporation - Windows Easy Transfer Post Migration Applic.) C:\Windows\system32\migwiz\postmig.exe =>.Microsoft Corporation
O4 - GS\SystemTools [Public]: Windows Easy Transfer.lnk . (.Microsoft Corporation - Windows Easy Transfer Application.) C:\Windows\system32\migwiz\migwiz.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O4 - GS\ProgramsCommon [Public]: Media Center.lnk . (.Microsoft Corporation - Windows Media Center.) C:\Windows\ehome\ehshell.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.) C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O4 - GS\ProgramsCommon [Public]: Sidebar.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe /showgadgets =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Anytime Upgrade.lnk . (.Microsoft Corporation - Windows Anytime Upgrade User Interface.) C:\Windows\system32\WindowsAnytimeUpgradeUI.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows DVD Maker.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\DVD Maker\DVDMaker.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation
O4 - GS\ProgramsCommon [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation

---\\ Winsock hijacker (Layered Service Provider) (4) - 1s
O10 - WLSP:\NameSpace_Catalog5\Catalog_Entries\000000000008\Winsock LSP File . (...) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Not File) =>Hijacker.Winsock
O10 - WLSP:\NameSpace_Catalog5\Catalog_Entries\000000000009\Winsock LSP File . (...) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Not File) =>Hijacker.Winsock
O10 - WLSP:\NameSpace_Catalog5\Catalog_Entries64\000000000008\Winsock LSP File . (...) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Not File) =>Hijacker.Winsock
O10 - WLSP:\NameSpace_Catalog5\Catalog_Entries64\000000000009\Winsock LSP File . (...) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Not File) =>Hijacker.Winsock

---\\ Hijackers (7) - 0s
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\..\{444988B6-9931-4F66-8E63-A199AE9754F2}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip\..\{539CB6FE-A5AF-4637-8F18-2DC6A160B884}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip\..\{846ee342-7039-11de-9d20-806e6f6e6963}: NameServer =
O17 - HKLM\System\CCS\Services\Tcpip\..\{05791D1D-051A-4ECE-A4F5-2DC4F9998DD0}: DhcpNameServer =
O17 - HKLM\System\CCS\Services\Tcpip\..\{539CB6FE-A5AF-4637-8F18-2DC6A160B884}: DhcpNameServer = =>.UK Milton Keynes Dedicated Server Hosting
O17 - HKLM\System\CCS\Services\Tcpip\..\{539CB6FE-A5AF-4637-8F18-2DC6A160B884}: DhcpDomain =

---\\ Extra protocols (20) - 1s
O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\System32\inetcomm.dll =>.Microsoft Corporation
O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\System32\urlmon.dll =>.Microsoft Corporation
O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\System32\itss.dll =>.Microsoft Corporation
O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\System32\MSVidCtl.dll =>.Microsoft Corporation
O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\System32\mshtml.dll =>.Microsoft Corporation
O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®
O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\System32\mscoree.dll =>.Microsoft Corporation®

---\\ Software installed (27) - 11s
O42 - Logiciel: Avast Free Antivirus - (.AVAST Software.) [HKLM][64Bits] -- Avast Antivirus =>.AVAST Software s.r.o.®
O42 - Logiciel: calibre 64bit - (.Kovid Goyal.) [HKLM][64Bits] -- {3E7334AB-3B64-4CD0-8DAC-817FF56AED7E} =>.Kovid Goyal
O42 - Logiciel: CDisplay 1.8 - (.dvd8n.) [HKLM][64Bits] -- CDisplay_is1 =>.dvd8n
O42 - Logiciel: Diablo II - (..) [HKLM][64Bits] -- Diablo II
O42 - Logiciel: Freedome - (.F-Secure Corporation.) [HKLM][64Bits] -- F-Secure Freedome =>.F-Secure Corporation®
O42 - Logiciel: Geeks3D FurMark - (.Geeks3D.) [HKLM][64Bits] -- {2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1 =>.Geeks3D
O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc®
O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc.
O42 - Logiciel: HostsMan 4.7.105 - ( [HKLM][64Bits] -- {1A3DD1A9-7B7B-4ECA-AD2F-98466F49F62C}_is1 =>
O42 - Logiciel: Imperium Galactica II - Alliances - ( [HKLM][64Bits] -- 1254614904_is1 =>.GOG Limited®
O42 - Logiciel: Intel(R) Graphics Media Accelerator Driver - (.Intel Corporation.) [HKLM][64Bits] -- {F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA} =>.Intel Corporation - Software and Firmware Products®
O42 - Logiciel: Mozilla Firefox 57.0 (x64 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Firefox 57.0 (x64 en-US) =>.Mozilla Corporation®
O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla
O42 - Logiciel: MSI Afterburner 4.4.0 - (.MSI Co., LTD.) [HKLM][64Bits] -- Afterburner =>.MSI Co., LTD
O42 - Logiciel: OpenOffice 4.1.4 - (.Apache Software Foundation.) [HKLM][64Bits] -- {4138A847-021B-4C26-B6BF-220B2446F603} =>.Apache Software Foundation
O42 - Logiciel: PeerBlock 1.2 (r693) - (.PeerBlock, LLC.) [HKLM][64Bits] -- {015C5B35-B678-451C-9AEE-821E8D69621C}_is1 =>.PeerBlock, LLC
O42 - Logiciel: PerformanceTest v9.0 - (.Passmark Software.) [HKLM][64Bits] -- PerformanceTest 9_is1 =>.PassMark Software Pty Ltd®
O42 - Logiciel: RivaTuner Statistics Server 7.0.0 - (.Unwinder.) [HKLM][64Bits] -- RTSS =>.Unwinder
O42 - Logiciel: Skype™ 7.40 - (.Skype Technologies S.A..) [HKLM][64Bits] -- {3B7E914A-93D5-4A29-92BB-AF8C3F66C431} =>.Skype Technologies S.A.
O42 - Logiciel: SpeedFan (remove only) - (.Almico Software.) [HKLM][64Bits] -- SpeedFan =>.Almico Software
O42 - Logiciel: STAR WARS® - Knights of the Old Republic™ - ( [HKLM][64Bits] -- 1207666283_is1 =>.GOG Limited®
O42 - Logiciel: System Ninja version 3.1.5 - (.SingularLabs.) [HKLM][64Bits] -- {6E67710E-206D-43AB-BF21-E7CD63056C55}_is1 =>.SingularLabs
O42 - Logiciel: Unchecky v1.1 - (.Reason Software Company Inc..) [HKLM][64Bits] -- Unchecky =>.Reason Software Company Inc.®
O42 - Logiciel: VirtualCloneDrive - (.Elaborate Bytes.) [HKLM][64Bits] -- VirtualCloneDrive =>.Elaborate Bytes
O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN
O42 - Logiciel: WinRAR 5.50 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH®
O42 - Logiciel: Wipe - ( [HKLM][64Bits] -- wipe =>.Yury Saprykin®

---\\ HKCU & HKLM Software Keys (72) - 11s
HKLM\SOFTWARE\Wow6432Node\ =>
HKLM\SOFTWARE\Wow6432Node\AVAST Software =>.AVAST Software
HKLM\SOFTWARE\Wow6432Node\AVG =>.AVG Software
HKLM\SOFTWARE\Wow6432Node\ =>.Games Software
HKLM\SOFTWARE\Wow6432Node\BioWare =>.BioWare
HKLM\SOFTWARE\Wow6432Node\Blizzard Entertainment =>.Blizzard Entertainment
HKLM\SOFTWARE\Wow6432Node\Comodo =>.Comodo
HKLM\SOFTWARE\Wow6432Node\Elaborate Bytes =>.Elaborate Bytes
HKLM\SOFTWARE\Wow6432Node\Eset =>.ESET
HKLM\SOFTWARE\Wow6432Node\F-Secure =>.F-Secure
HKLM\SOFTWARE\Wow6432Node\Foolish IT =>.Foolish IT
HKLM\SOFTWARE\Wow6432Node\ =>
HKLM\SOFTWARE\Wow6432Node\Google =>.Google
HKLM\SOFTWARE\Wow6432Node\IM Providers =>.IM Providers
HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel
HKLM\SOFTWARE\Wow6432Node\Licenses =>.Microsoft Corporation
HKLM\SOFTWARE\Wow6432Node\Malwarebytes Anti-Rootkit =>.Malwarebytes
HKLM\SOFTWARE\Wow6432Node\MicroWorld =>.MicroWorld Technologies Inc.
HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla
HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions
HKLM\SOFTWARE\Wow6432Node\OpenOffice =>.SourceForge
HKLM\SOFTWARE\Wow6432Node\Skype =>.Skype
HKLM\SOFTWARE\Wow6432Node\SpeedFan =>.Almico Software
HKLM\SOFTWARE\Wow6432Node\Unchecky =>.RaMMicHaeL
HKLM\SOFTWARE\Wow6432Node\Unwinder =>.Unwinder
HKLM\SOFTWARE\Wow6432Node\VideoLAN =>.VideoLAN
HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation
HKCU\SOFTWARE\9-lab =>.9-lab
HKCU\SOFTWARE\Avast Software =>.AVAST Software
HKCU\SOFTWARE\ =>.Games Software
HKCU\SOFTWARE\BillP Studios =>.BillP Studios
HKCU\SOFTWARE\Blizzard Entertainment =>.Blizzard Entertainment
HKCU\SOFTWARE\CDisplay =>.David Ayton
HKCU\SOFTWARE\Comodo =>.Comodo
HKCU\SOFTWARE\ComodoGroup =>.ComodoGroup
HKCU\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes
HKCU\SOFTWARE\F-Secure =>.F-Secure
HKCU\SOFTWARE\Google =>.Google
HKCU\SOFTWARE\IM Providers =>.IM Providers
HKCU\SOFTWARE\Intel =>.Intel
HKCU\SOFTWARE\LogiShrd =>.LogiShrd
HKCU\SOFTWARE\MicroWorld =>.MicroWorld Technologies Inc.
HKCU\SOFTWARE\Mozilla =>.Mozilla
HKCU\SOFTWARE\OpenOffice =>.SourceForge
HKCU\SOFTWARE\ProtectedStorage =>.Microsoft Corporation
HKCU\SOFTWARE\QtProject =>.QtProject
HKCU\SOFTWARE\Reason =>.Propellerhead
HKCU\SOFTWARE\Skype =>.Skype
HKCU\SOFTWARE\SpeedFan =>.Almico Software
HKCU\SOFTWARE\Strahinja Markovic =>.Strahinja Markovic
HKCU\SOFTWARE\Sysinternals =>.Sysinternals
HKCU\SOFTWARE\techPowerUp =>.TechPowerUp
HKCU\SOFTWARE\Trolltech =>.Trolltech
HKCU\SOFTWARE\Unchecky =>.RaMMicHaeL
HKCU\SOFTWARE\Unwinder =>.Unwinder
HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation
HKCU\SOFTWARE\Zemana =>.Zemana
HKCU\SOFTWARE\ZHP =>.Nicolas Coolman

---\\ Contents of the Common Files folders (170) - 7s
O43 - CFD: 21/11/2017 - [0] D -- \Program Files\9-lab =>.9-lab
O43 - CFD: 05/10/2017 - [] D -- \Program Files\AVAST Software =>.AVAST Software s.r.o.®
O43 - CFD: 10/11/2017 - [] D -- \Program Files\Calibre2 =>.Kovid Goyal
O43 - CFD: 13/07/2009 - [] D -- \Program Files\Common Files =>.Microsoft Corporation
O43 - CFD: 24/11/2017 - [] D -- \Program Files\COMODO =>.Comodo Group.
O43 - CFD: 05/10/2017 - [] D -- \Program Files\DVD Maker =>.Aone Software
O43 - CFD: 15/11/2017 - [] D -- \Program Files\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [] D -- \Program Files\Microsoft Games =>.Microsoft Corporation
O43 - CFD: 19/11/2017 - [] D -- \Program Files\Mozilla Firefox =>.Mozilla
O43 - CFD: 13/07/2009 - [] D -- \Program Files\MSBuild =>.Microsoft Corporation
O43 - CFD: 19/11/2017 - [] D -- \Program Files\PeerBlock =>.PeerBlock, LLC®
O43 - CFD: 15/11/2017 - [] D -- \Program Files\PerformanceTest =>.PassMark Software Pty Ltd®
O43 - CFD: 06/10/2017 - [] D -- \Program Files\Reason
O43 - CFD: 13/07/2009 - [] D -- \Program Files\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] D -- \Program Files\VideoLAN =>.VideoLan Team
O43 - CFD: 05/10/2017 - [] D -- \Program Files\Windows Defender =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [] D -- \Program Files\Windows Mail =>.Microsoft Corporation
O43 - CFD: 15/11/2017 - [] D -- \Program Files\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- \Program Files\Windows NT =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [] D -- \Program Files\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 20/11/2010 - [] D -- \Program Files\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [] D -- \Program Files\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 06/10/2017 - [] D -- \Program Files\WinRAR =>.win.rar GmbH®
O43 - CFD: 15/11/2017 - [] D -- \Program Files\Wipe =>.Yuri Saprykin
O43 - CFD: 06/10/2017 - [] D -- C:\Program Files (x86)\CDisplay
O43 - CFD: 20/11/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files (x86)\Diablo II =>.Blizzard Entertainment
O43 - CFD: 04/11/2017 - [] D -- C:\Program Files (x86)\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 24/11/2017 - [] D -- C:\Program Files (x86)\F-Secure =>.F-Secure Corporation®
O43 - CFD: 15/11/2017 - [] D -- C:\Program Files (x86)\Geeks3D =>.Geeks3D
O43 - CFD: 05/10/2017 - [] D -- C:\Program Files (x86)\Google =>.Google Inc®
O43 - CFD: 06/10/2017 - [] D -- C:\Program Files (x86)\HostsMan
O43 - CFD: 05/10/2017 - [] D -- C:\Program Files (x86)\Intel =>.Intel Corporation
O43 - CFD: 15/11/2017 - [] D -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation
O43 - CFD: 04/10/2017 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation
O43 - CFD: 17/11/2017 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation
O43 - CFD: 15/11/2017 - [] D -- C:\Program Files (x86)\MSI Afterburner =>.Micro-Star International Co
O43 - CFD: 05/11/2017 - [] D -- C:\Program Files (x86)\OpenOffice 4 =>
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation
O43 - CFD: 15/11/2017 - [] D -- C:\Program Files (x86)\RivaTuner Statistics Server =>.RivaTuner
O43 - CFD: 24/11/2017 - [] D -- C:\Program Files (x86)\Ruiware =>.Ruiware, LLC®
O43 - CFD: 07/10/2017 - [] D -- C:\Program Files (x86)\Sigil =>.John Schember Sigil
O43 - CFD: 10/10/2017 - [] RD -- C:\Program Files (x86)\Skype =>.Skype
O43 - CFD: 16/11/2017 - [] D -- C:\Program Files (x86)\SpeedFan =>.Almico Software
O43 - CFD: 21/11/2017 - [] D -- C:\Program Files (x86)\System Ninja
O43 - CFD: 05/10/2017 - [] D -- C:\Program Files (x86)\Unchecky =>.RaMMicHaeL
O43 - CFD: 05/10/2017 - [] D -- C:\Program Files (x86)\VideoLAN =>.VideoLan Team
O43 - CFD: 05/10/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation
O43 - CFD: 15/11/2017 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation
O43 - CFD: 20/11/2010 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation
O43 - CFD: 12/04/2011 - [] D -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation
O43 - CFD: 21/11/2017 - [0] D -- C:\Program Files (x86)\Zemana AntiMalware =>.Zemana
O43 - CFD: 24/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
O43 - CFD: 06/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software =>.AVAST Software
O43 - CFD: 10/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management =>.Kovid Goyal
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDisplay
O43 - CFD: 05/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II =>.Blizzard Entertainment
O43 - CFD: 04/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes =>.Elaborate Bytes
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freedome
O43 - CFD: 17/11/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 15/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D =>.Geeks3D
O43 - CFD: 17/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ =>
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HostsMan
O43 - CFD: 06/10/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 05/11/2017 - [] SD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.4 =>.SourceForge
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeerBlock =>.PeerBlock
O43 - CFD: 15/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PerformanceTest
O43 - CFD: 10/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype =>.Skype
O43 - CFD: 13/07/2009 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Ninja
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky =>.RaMMicHaeL
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team
O43 - CFD: 21/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol =>.Bill2 Software
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 15/11/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wipe =>.Yuri Saprykin
O43 - CFD: 14/11/2017 - [] D -- C:\ProgramData\9-lab =>.9-lab
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\ =>
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\AVAST Software =>.AVAST Software
O43 - CFD: 08/11/2017 - [] D -- C:\ProgramData\Blizzard Entertainment =>.Blizzard Entertainment
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\Common Files =>.Microsoft Corporation
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\Comodo =>.Comodo Group.
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\Comodo Downloader
O43 - CFD: 22/10/2017 - [] D -- C:\ProgramData\Dell =>.Dell
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation
O43 - CFD: 15/11/2017 - [] D -- C:\ProgramData\Emsisoft =>.Emsisoft
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\F-Secure =>.F-Secure
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Favorites =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\Foolish IT =>.Foolish IT
O43 - CFD: 24/11/2017 - [] D -- C:\ProgramData\HitmanPro =>.EIDOS hitman Game
O43 - CFD: 21/11/2017 - [] D -- C:\ProgramData\HitmanPro.Alert =>.Eidos
O43 - CFD: 05/10/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes
O43 - CFD: 05/10/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation
O43 - CFD: 12/10/2017 - [] D -- C:\ProgramData\MicroWorld =>.MicroWorld Technologies Inc.
O43 - CFD: 15/11/2017 - [] D -- C:\ProgramData\Passmark =>.PassMark Software
O43 - CFD: 14/10/2017 - [] D -- C:\ProgramData\RogueKiller =>.Adlice Software
O43 - CFD: 21/11/2017 - [0] D -- C:\ProgramData\Shared Space =>.Comodo Group.
O43 - CFD: 10/10/2017 - [] D -- C:\ProgramData\Skype =>.Skype
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation
O43 - CFD: 24/11/2017 - [0] D -- C:\ProgramData\SWCUTemp
O43 - CFD: 20/11/2017 - [0] AD -- C:\ProgramData\TEMP =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation
O43 - CFD: 05/11/2017 - [] D -- C:\ProgramData\Unchecky =>.RaMMicHaeL
O43 - CFD: 06/10/2017 - [] D -- C:\ProgramData\Western Digital =>.Western Digital
O43 - CFD: 05/10/2017 - [] D -- C:\Program Files (x86)\Common Files\microsoft shared =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation
O43 - CFD: 10/10/2017 - [] D -- C:\Program Files (x86)\Common Files\Skype =>.Skype
O43 - CFD: 13/07/2009 - [] D -- C:\Program Files (x86)\Common Files\SpeechEngines =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation
O43 - CFD: 24/11/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\9-lab =>.9-lab
O43 - CFD: 06/10/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\ =>
O43 - CFD: 05/10/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\AVAST Software =>.AVAST Software
O43 - CFD: 21/11/2017 - [] SD -- C:\Users\Patrick\AppData\Roaming\Microsoft =>.Microsoft Corporation
O43 - CFD: 21/11/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Mozilla =>.Mozilla Corporation
O43 - CFD: 18/10/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Skype =>.Skype
O43 - CFD: 07/10/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\uTorrent
O43 - CFD: 06/10/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\vlc =>.VideoLan Team
O43 - CFD: 07/10/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\WinPatrol =>.Bill2 Software
O43 - CFD: 20/11/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Wipe =>.Yuri Saprykin
O43 - CFD: 24/11/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\ZHP =>.Nicolas Coolman
O43 - CFD: 04/10/2017 - [0] SHD -- C:\Users\Patrick\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] D -- C:\Users\Patrick\AppData\Local\Comodo =>.Comodo Group.
O43 - CFD: 22/11/2017 - [] D -- C:\Users\Patrick\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 24/11/2017 - [] D -- C:\Users\Patrick\AppData\Local\ESET =>.ESET
O43 - CFD: 05/10/2017 - [] D -- C:\Users\Patrick\AppData\Local\F-Secure =>.F-Secure
O43 - CFD: 07/10/2017 - [] D -- C:\Users\Patrick\AppData\Local\Google =>.Google
O43 - CFD: 17/10/2017 - [] D -- C:\Users\Patrick\AppData\Local\GyroscopeGames
O43 - CFD: 04/10/2017 - [0] SHD -- C:\Users\Patrick\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 21/11/2017 - [] D -- C:\Users\Patrick\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 21/11/2017 - [] D -- C:\Users\Patrick\AppData\Local\Mozilla =>.Mozilla Corporation
O43 - CFD: 15/11/2017 - [] D -- C:\Users\Patrick\AppData\Local\PassMark =>.PassMark Software
O43 - CFD: 21/11/2017 - [] D -- C:\Users\Patrick\AppData\Local\Programs =>.Microsoft Corporation
O43 - CFD: 24/11/2017 - [] D -- C:\Users\Patrick\AppData\Local\Temp =>.Microsoft Corporation
O43 - CFD: 04/10/2017 - [0] SHD -- C:\Users\Patrick\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 07/10/2017 - [] D -- C:\Users\Patrick\AppData\Local\Western Digital =>.Western Digital
O43 - CFD: 05/10/2017 - [] D -- C:\Users\Patrick\AppData\Local\Zemana =>.Zemana
O43 - CFD: 19/11/2017 - [] D -- C:\Users\Patrick\AppData\Local\ZHP =>.Nicolas Coolman
O43 - CFD: 21/11/2017 - [0] D -- C:\Users\Patrick\AppData\Local\Programs\Common =>.Microsoft Corporation
O43 - CFD: 07/10/2017 - [] D -- C:\Users\Patrick\Desktop\Tor Browser =>.Roger Dingledine
O43 - CFD: 06/10/2017 - [] RD -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] RD -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools
O43 - CFD: 04/11/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Diablo II =>.Blizzard Entertainment
O43 - CFD: 14/11/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation
O43 - CFD: 06/10/2017 - [] RD -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation
O43 - CFD: 15/11/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner =>.Micro-Star International Co
O43 - CFD: 15/11/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server =>.RivaTuner
O43 - CFD: 25/10/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan =>.Almico Software
O43 - CFD: 07/10/2017 - [] RD -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation
O43 - CFD: 06/10/2017 - [] D -- C:\Users\Patrick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR
O43 - CFD: 13/07/2009 - [0] SHD -- \Users\Default\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- \Users\Default\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- \Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 18/11/2017 - [0] D -- \Users\Default\AppData\Local\temp =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- \Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- \Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- \Users\Default User\AppData\Local\History =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- \Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 18/11/2017 - [0] D -- \Users\Default User\AppData\Local\temp =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [0] SHD -- \Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation
O43 - CFD: 21/11/2017 - [0] -- C:\Windows\System32\Config\systemprofile\AppData\Local\CrashDumps =>.Microsoft Corporation
O43 - CFD: 13/07/2009 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation
O43 - CFD: 05/10/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Zemana =>.Zemana
O43 - CFD: 13/07/2009 - [] SD -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\Microsoft =>.Microsoft Corporation

---\\ ShellIconOverlayIdentifiers (SIOI) (4) - 0s
O106 - SIOI: avast [00asw] - {472083B0-C522-11CF-8763-00608CC02F24}. (.AVAST Software - Avast Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShA64.dll =>.AVAST Software s.r.o.®
O106 - SIOI: avast [00avg] - {472083B0-C522-11CF-8763-00608CC02F24}. (.AVAST Software - Avast Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShA64.dll =>.AVAST Software s.r.o.®
O106 - SIOI: Enhanced Storage Icon Overlay Handler Class [EnhancedStorageShell] - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}. (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O106 - SIOI: Sharing Overlay (Private) [SharingPrivate] - {08244EE6-92F0-47f2-9FC9-929BAA2E7235}. (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation

---\\ Search Context Menu Handlers (SCMH) (31) - 1s
O108 - CMH1: avast [64Bits] - {472083B0-C522-11CF-8763-00608CC02F24} . (.AVAST Software - Avast Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShA64.dll =>.AVAST Software s.r.o.®
O108 - CMH1: BriefcaseMenu [64Bits] - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Windows Briefcase.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH1: Glary Utilities [64Bits] - {B3C418F8-922B-4faf-915E-59BC14448CF7} . (.Orphan.)
O108 - CMH1: Open With [64Bits] - {09799AFB-AD67-11d1-ABCD-00C04FC30936} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH1: Open With EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH1: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH1: VirtualCloneDrive [64Bits] - {B7056B8E-4F99-44f8-8CBD-282390FE5428} . (.Elaborate Bytes AG - CloseTray.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll =>.Elaborate Bytes AG®
O108 - CMH1: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH®
O108 - CMH2: Compatibility [64Bits] - {1d27f844-3a1f-4410-85ac-14651078412d} . (.Microsoft Corporation - Compatibility Tab Shell Extension Library.) -- C:\Windows\System32\acppage.dll =>.Microsoft Corporation
O108 - CMH2: OpenContainingFolderMenu [64Bits] - {37ea3a21-7493-4208-a011-7f9ea79ce9f5} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: 00asw [64Bits] - {472083B0-C522-11CF-8763-00608CC02F24} . (.AVAST Software - Avast Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShA64.dll =>.AVAST Software s.r.o.®
O108 - CMH3: CopyAsPathMenu [64Bits] - {f3d06e7c-1e45-4a26-847e-f9fcdee59be0} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH3: SendTo [64Bits] - {7BA4C740-9E81-11CF-99D3-00AA004AE837} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH4: EncryptionMenu [64Bits] - {A470F8CF-A1E8-4f65-8335-227475AA5C46} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH4: MSSE [64Bits] - {0365FE2C-F183-4091-AC82-BFC39FB75C49} . (.Orphan.)
O108 - CMH4: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Orphan.)
O108 - CMH4: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH5: Gadgets [64Bits] - {6B9228DA-9C15-419e-856C-19E768A13BDC} . (.Microsoft Corporation - Sidebar droptarget.) -- \Program Files\Windows Sidebar\sbdrop.dll =>.Microsoft Corporation
O108 - CMH5: igfxcui [64Bits] - {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} . (.Intel Corporation - igfxpph Module.) -- C:\Windows\system32\igfxpph.dll =>.Intel Corporation
O108 - CMH5: New [64Bits] - {D969A300-E7FF-11d0-A93B-00A0C90F2719} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH5: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH6: avast [64Bits] - {472083B0-C522-11CF-8763-00608CC02F24} . (.AVAST Software - Avast Shell Extension.) -- C:\Program Files\AVAST Software\Avast\ashShA64.dll =>.AVAST Software s.r.o.®
O108 - CMH6: BriefcaseMenu [64Bits] - {85BBD920-42A0-1069-A2E4-08002B30309D} . (.Microsoft Corporation - Windows Briefcase.) -- C:\Windows\System32\syncui.dll =>.Microsoft Corporation
O108 - CMH6: Glary Utilities [64Bits] - {B3C418F8-922B-4faf-915E-59BC14448CF7} . (.Orphan.)
O108 - CMH6: Library Location [64Bits] - {3dad6c5d-2167-4cae-9914-f99e41c12cfa} . (.Microsoft Corporation - Windows Shell Common Dll.) -- C:\Windows\System32\shell32.dll =>.Microsoft Corporation
O108 - CMH6: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Orphan.)
O108 - CMH6: WinRAR [64Bits] - {B41DB860-64E4-11D2-9906-E49FADC173CA} . (.Alexander Roshal - WinRAR shell extension.) -- C:\Program Files\WinRAR\RarExt.dll =>.win.rar GmbH®
O108 - CMH7: EnhancedStorageShell [64Bits] - {2854F705-3548-414C-A113-93E27C808C85} . (.Microsoft Corporation - Windows Enhanced Storage Shell Extension DL.) -- C:\Windows\System32\EhStorShell.dll =>.Microsoft Corporation
O108 - CMH7: Glary Utilities [64Bits] - {B3C418F8-922B-4faf-915E-59BC14448CF7} . (.Orphan.)
O108 - CMH7: Sharing [64Bits] - {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} . (.Microsoft Corporation - Shell extensions for sharing.) -- C:\Windows\System32\ntshrui.dll =>.Microsoft Corporation
O108 - CMH7: VirtualCloneDrive [64Bits] - {B7056B8E-4F99-44f8-8CBD-282390FE5428} . (.Elaborate Bytes AG - CloseTray.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll =>.Elaborate Bytes AG®

---\\ ShareTools MSconfig StartupReg (2) - 1s
O53 - SMSR:HKLM\...\startupreg\uTorrent [Key] [64Bits] . (.BitTorrent Inc. - µTorrent.) -- C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
O53 - SMSR:HKLM\...\startupreg\Wipe Maintance [Key] [64Bits] . ( - Application Installer.) -- C:\Program Files\Wipe\net1.exe =>

---\\ System Drivers List (65) - 9s
O58 - SDL:2017/11/18 20:59:22 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\Windows\System32\drivers\4B53E2E4.sys [255928] =>.Malwarebytes Corporation®
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec Windows SAS/SATA Storport Driver.) -- C:\Windows\System32\drivers\adp94xx.sys [491088] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec Windows SATA Storport Driver.) -- C:\Windows\System32\drivers\adpahci.sys [339536] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec StorPort Ultra320 SCSI Driver (X64).) -- C:\Windows\System32\drivers\adpu320.sys [182864] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:52:21 A . (.Acer Laboratories Inc. - ALi mini IDE Driver.) -- C:\Windows\System32\drivers\aliide.sys [15440] =>.Microsoft Windows®
O58 - SDL:2011/03/10 22:41:12 A . (.Advanced Micro Devices - AHCI 1.2 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [107904] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:52:20 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [194128] =>.Microsoft Windows®
O58 - SDL:2011/03/10 22:41:12 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [27008] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec RAID Storport Driver.) -- C:\Windows\System32\drivers\arc.sys [87632] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:52:21 A . (.Adaptec, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [97856] =>.Microsoft Windows®
O58 - SDL:2017/11/24 10:20:01 A . (.AVAST Software - Avast anti rootkit.) -- C:\Windows\System32\drivers\aswArPot.sys [185120] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:19:26 A . (.AVAST Software - IDS Application Activity Monitor Driver..) -- C:\Windows\System32\drivers\aswbidsdrivera.sys [321032] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:19:27 A . (.AVAST Software - Application Activity Monitor Helper Driver.) -- C:\Windows\System32\drivers\aswbidsha.sys [199480] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:19:27 A . (.AVAST Software - Logging Driver.) -- C:\Windows\System32\drivers\aswbloga.sys [343792] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:19:27 A . (.AVAST Software - Universal Driver.) -- C:\Windows\System32\drivers\aswbuniva.sys [57720] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:20:02 A . (.AVAST Software - Avast HWID.) -- C:\Windows\System32\drivers\aswHwid.sys [47008] =>.AVAST Software s.r.o.® (.AVAST Software)
O58 - SDL:2017/11/24 10:20:02 A . (.AVAST Software - Avast File System Minifilter for Windows 20.) -- C:\Windows\System32\drivers\aswMonFlt.sys [148288] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:20:01 A . (.AVAST Software - Avast WFP Redirect Driver.) -- C:\Windows\System32\drivers\aswRdr2.sys [110376] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:20:02 A . (.AVAST Software - Avast Revert.) -- C:\Windows\System32\drivers\aswRvrt.sys [84416] =>.AVAST Software s.r.o.® (.AVAST Software)
O58 - SDL:2017/11/24 10:19:33 A . (.AVAST Software - Avast Virtualization Driver.) -- C:\Windows\System32\drivers\aswSnx.sys [1026232] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:20:02 A . (.AVAST Software - Avast self protection module.) -- C:\Windows\System32\drivers\aswSP.sys [456912] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:20:02 A . (.AVAST Software - Stream Filter.) -- C:\Windows\System32\drivers\aswStm.sys [204488] =>.AVAST Software s.r.o.®
O58 - SDL:2017/11/24 10:20:02 A . (.AVAST Software - Avast VM Monitor.) -- C:\Windows\System32\drivers\aswVmm.sys [367016] =>.AVAST Software s.r.o.® (.AVAST Software)
O58 - SDL:2009/06/10 12:34:23 A . (.Broadcom Corporation - Broadcom NetXtreme Gigabit Ethernet NDIS6.x.) -- C:\Windows\System32\drivers\b57nd60a.sys [270848] =>.Broadcom Corporation
O58 - SDL:2009/07/07 23:45:50 A . (.Broadcom Corporation - Broadcom 802.11 Network Adapter wireless dr.) -- C:\Windows\System32\drivers\BCMWL664.SYS [2769400] =>.Broadcom Corporation®
O58 - SDL:2009/06/10 12:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Lower.) -- C:\Windows\System32\drivers\BrFiltLo.sys [18432] =>.Brother Industries, Ltd.
O58 - SDL:2009/06/10 12:41:06 A . (.Brother Industries, Ltd. - Windows ME USB Mass-Storage Bulk-Only Upper.) -- C:\Windows\System32\drivers\BrFiltUp.sys [8704] =>.Brother Industries, Ltd.
O58 - SDL:2009/07/13 17:19:07 A . (.Brother Industries Ltd. - Brotehr Serial I/F Driver (WDM).) -- C:\Windows\System32\drivers\BrSerId.sys [286720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 12:41:10 A . (.Brother Industries Ltd. - Brother Serial driver (WDM version).) -- C:\Windows\System32\drivers\BrSerWdm.sys [47104] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 12:41:10 A . (.Brother Industries Ltd. - Brother USB MDM Driver.) -- C:\Windows\System32\drivers\BrUsbMdm.sys [14976] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 12:41:10 A . (.Brother Industries Ltd. - Brother USB Serial Driver.) -- C:\Windows\System32\drivers\BrUsbSer.sys [14720] =>.Brother Industries Ltd.
O58 - SDL:2009/06/10 12:34:28 A . (.Broadcom Corporation - Broadcom NetXtreme II GigE VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [468480] =>.Broadcom Corporation
O58 - SDL:2009/07/13 17:52:31 A . (.CMD Technology, Inc. - CMD PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\cmdide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2014/12/20 14:31:04 A . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) -- C:\Windows\System32\drivers\ElbyCDIO.sys [40344] =>.Elaborate Bytes AG®
O58 - SDL:2009/07/13 17:47:48 A . (.Emulex - Storport Miniport Driver for LightPulse HBA.) -- C:\Windows\System32\drivers\elxstor.sys [530496] =>.Microsoft Windows®
O58 - SDL:2009/06/10 12:34:33 A . (.Broadcom Corporation - Broadcom NetXtreme II 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3286016] =>.Broadcom Corporation
O58 - SDL:2017/10/05 17:36:11 A . (.The OpenVPN Project - TAP-Windows Virtual Network Driver (NDIS 6..) -- C:\Windows\System32\drivers\fsfreedometap.sys [34344] =>.F-Secure Corporation®
O58 - SDL:2017/10/06 08:12:08 A . (.Glarysoft Ltd - The driver for the Startup Manager tool.) -- C:\Windows\System32\drivers\GUBootStartup.sys [20160] =>.Glarysoft Ltd®
O58 - SDL:2009/06/10 12:31:59 A . (.Hauppauge Computer Works, Inc. - Hauppauge WinTV 885 Consumer IR Driver for.) -- C:\Windows\System32\drivers\hcw85cir.sys [31232] =>.Hauppauge Computer Works, Inc.
O58 - SDL:2010/11/20 19:23:47 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [78720] =>.Microsoft Windows®
O58 - SDL:2011/03/10 22:41:26 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [410496] =>.Microsoft Windows®
O58 - SDL:2012/11/14 15:57:06 A . (.Intel Corporation - Intel Graphics Kernel Mode Driver.) -- C:\Windows\System32\drivers\igdkmd64.sys [10629408] =>.Intel Corporation
O58 - SDL:2009/07/13 17:48:04 A . (.Intel Corp./ICP vortex GmbH - Intel/ICP Raid Storport Driver.) -- C:\Windows\System32\drivers\iirsp.sys [44112] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - LSI Fusion-MPT FC Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_fc.sys [114752] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [106560] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2.sys [65600] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - LSI Fusion-MPT SCSI Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_scsi.sys [115776] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [35392] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:48:04 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\MegaSR.sys [284736] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:48:26 A . (.IBM Corporation - IBM ServeRAID Controller Driver.) -- C:\Windows\System32\drivers\nfrd960.sys [51264] =>.Microsoft Windows®
O58 - SDL:2011/03/10 22:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [148352] =>.Microsoft Windows®
O58 - SDL:2011/03/10 22:41:34 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166272] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:45:46 A . (.QLogic Corporation - QLogic Fibre Channel Stor Miniport Driver.) -- C:\Windows\System32\drivers\ql2300.sys [1524816] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:45:45 A . (.QLogic Corporation - QLogic iSCSI Storport Miniport Driver.) -- C:\Windows\System32\drivers\ql40xx.sys [128592] =>.Microsoft Windows®
O58 - SDL:2009/06/10 12:37:19 A . (.Macrovision Corporation, Macrovision Europe Limited, - Macrovision SECURITY Driver.) -- C:\Windows\System32\drivers\secdrv.sys [23040] =>.Macrovision Corporation, Macrovision Europe Limited,
O58 - SDL:2009/07/13 17:45:45 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [43584] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:45:46 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [80464] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:45:55 A . (.Promise Technology - Promise SuperTrak EX Series Driver for Win.) -- C:\Windows\System32\drivers\stexstor.sys [24656] =>.Microsoft Windows®
O58 - SDL:2017/11/19 12:08:21 A . (...) -- C:\Windows\System32\drivers\TrueSight.sys [28272] =>.Adlice®
O58 - SDL:2017/10/12 22:37:18 A . (.BitDefender S.R.L. - Trufos Kernel Module.) -- C:\Windows\System32\drivers\trufos.sys [350160] =>.Bitdefender SRL®
O58 - SDL:2013/07/24 07:02:46 A . (.Elaborate Bytes AG - Virtual CloneDrive SCSI miniport.) -- C:\Windows\System32\drivers\VClone.sys [36864] =>.Elaborate Bytes AG
O58 - SDL:2009/07/13 17:45:55 A . (.VIA Technologies, Inc. - VIA Generic PCI IDE Bus Driver.) -- C:\Windows\System32\drivers\viaide.sys [17488] =>.Microsoft Windows®
O58 - SDL:2009/07/13 17:45:55 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [161872] =>.Microsoft Windows®
O58 - SDL:2015/04/29 23:01:06 A . (.Western Digital Technologies - WD SCSI Architecture Model (SAM) driver.) -- C:\Windows\System32\drivers\wdcsam64.sys [23200] =>.Microsoft Windows Hardware Compatibility Publisher®
O58 - SDL:2009/09/28 08:22:00 A . (.©Copyright 2002-2009 Marvell®. All rights reserved. - .) -- C:\Windows\System32\drivers\yk62x64.sys [395264] =>.©Copyright 2002-2009 Marvell®. All rights reserved.

---\\ File Associations Shell Spawning (10) - 0s
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %*
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (...) -- %1" %*
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation
O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S

---\\ Start Menu Internet (12) - 1s
O68 - StartMenuInternet: <Firefox-308046B0AF4A39CB> <Mozilla Firefox> [64Bits][HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe =>.Mozilla Corporation®
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc®
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation®
O68 - StartMenuInternet: <Firefox-308046B0AF4A39CB> <Mozilla Firefox> [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <Firefox-308046B0AF4A39CB> <Mozilla Firefox> [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation
O68 - StartMenuInternet: <Firefox-308046B0AF4A39CB> <Mozilla Firefox> [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Mozilla Corporation - Firefox Helper.) -- C:\Program Files\Mozilla Firefox\uninstall\helper.exe =>.Mozilla Corporation
O68 - StartMenuInternet: <Google Chrome> <Google Chrome> [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc.
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer> [64Bits][HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation

---\\ Search Browser Infection (3) - 29s
O69 - SBI: SearchScopes [HKCU] [64Bits]{012E1000-F331-11DB-8314-0800200C9A66} - (Google) - =>.Google Inc.
O69 - SBI: SearchScopes [HKCU] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (Bing) - =>
O69 - SBI: SearchScopes [HKLM] [64Bits]{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - (@ieframe.dll,-12512) - =>

---\\ Search Svchost Services (32) - 1s
O83 - Search Svchost Services: AeLookupSvc (AeLookupSvc) . (.Microsoft Corporation - Application Experience Service.) -- C:\Windows\System32\aelupsvc.dll [72192] =>.Microsoft Corporation
O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [80384] =>.Microsoft Corporation
O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\System32\srvsvc.dll [236032] =>.Microsoft Corporation
O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [794624] =>.Microsoft Corporation
O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [859648] =>.Microsoft Corporation
O83 - Search Svchost Services: AudioSrv (AudioSrv) . (.Microsoft Corporation - Windows Audio Service.) -- C:\Windows\System32\Audiosrv.dll [680448] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [99328] =>.Microsoft Corporation
O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [344064] =>.Microsoft Corporation
O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [97792] =>.Microsoft Corporation
O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\sens.dll [64512] =>.Microsoft Corporation
O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [359424] =>.Microsoft Corporation
O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [316928] =>.Microsoft Corporation
O83 - Search Svchost Services: TermService (TermService) . (.Microsoft Corporation - Remote Desktop Session Host Server Remote C.) -- C:\Windows\System32\termsrv.dll [683520] =>.Microsoft Corporation
O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\System32\wuaueng.dll [2651136] =>.Microsoft Corporation
O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [849920] =>.Microsoft Corporation
O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [370688] =>.Microsoft Corporation
O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [569344] =>.Microsoft Corporation
O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\system32\seclogon.dll [30720] =>.Microsoft Corporation
O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [70144] =>.Microsoft Corporation
O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\System32\iscsiexe.dll [156672] =>.Microsoft Corporation
O83 - Search Svchost Services: MMCSS (MMCSS) . (.Microsoft Corporation - Multimedia Class Scheduler Service.) -- C:\Windows\System32\mmcss.dll [67584] =>.Microsoft Corporation
O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\System32\wbem\WMIsvc.dll [242688] =>.Microsoft Corporation
O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\sessenv.dll [121856] =>.Microsoft Corporation
O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [136704] =>.Microsoft Corporation
O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [111104] =>.Microsoft Corporation
O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\System32\schedsvc.dll [1110016] =>.Microsoft Corporation
O83 - Search Svchost Services: hkmsvc (hkmsvc) . (.Microsoft Corporation - Key Management Service.) -- C:\Windows\System32\kmsvc.dll [90624] =>.Microsoft Corporation
O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [84480] =>.Microsoft Corporation
O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\System32\profsvc.dll [210432] =>.Microsoft Corporation
O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\System32\themeservice.dll [44544] =>.Microsoft Corporation
O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [100864] =>.Microsoft Corporation

---\\ Windows Installer Scan (4) - 2s
[MD5.E81C668B81975567E8C5728B805704E2] [WIS][2017/10/05 10:48:59] (.Google Inc. - Google Update Helper.) -- C:\Windows\Installer\1774a7.msi [40960] =>.Google Inc.
[MD5.9B06565DD7D90989169163A51199BE36] [WIS][2017/10/10 11:48:21] (.Skype Technologies S.A. - Skype.) -- C:\Windows\Installer\1a9b3a.msi [45539328] =>.Skype Technologies S.A.
[MD5.2919393606551EF00AE29CF569D307DA] [WIS][2017/09/22 05:42:44] (.OpenOffice - OpenOffice 4.1.4.) -- C:\Windows\Installer\2036e73.msi [2310144] =>.OpenOffice
[MD5.86FA61739CA55AB2F8E05E97709D0E55] [WIS][2017/11/10 17:03:06] (.Kovid Goyal - calibre Installer.) -- C:\Windows\Installer\cac4e.msi [69115904] =>.Kovid Goyal

---\\ Additional Scan (O88) (8) - 1s
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Glary Utilities =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} =>.SUP.Orphan
HKLM\Software\Wow6432Node\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} =>.SUP.Orphan
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MSSE =>.SUP.Orphan
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Glary Utilities =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files =>.SUP.Orphan
HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Glary Utilities =>.SUP.Orphan

---\\ Summary of the elements found (1) - 0s =>.SUP.Orphan

~ Unselected Options:
~ End of the scan, 9926 items in 02mn14s (859)(0)
Hello PatL,
Please run the FRST fix below.

Please left click on the attached Fixlist.txt file at the bottom of this post. On the dialogue box that opens click "Save File" and then "OK"


Select a location then save the file. IMPORTANT the fixlist.txt file must be in the same location as the FRST program otherwise the fix will not work.


To run the fix right click the FRST icon and choose "Run as Administrator" then click on "Fix"


Depending on the amount of data to be moved it may take a few minutes to complete, and the computer may reboot. When the fix is complete and/or the computer has rebooted the "Fixlist.txt" file you created will be renamed "Fixlog.txt"

Please copy and paste the contents of that file in your next post🙂


Fix result of Farbar Recovery Scan Tool (x64) Version: 19-11-2017
Ran by Patrick (24-11-2017 15:05:54) Run:9
Running from C:\Users\Owner\Desktop
Loaded Profiles: Patrick & Owner & Administrator (Available Profiles: Patrick & Owner & Administrator)
Boot Mode: Normal

fixlist content:
HKLM\...\RunOnce: [CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}] => C:\ProgramData\cis7D3A.exe [4784832 2017-08-29] (COMODO)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1492466166-1735938548-1690570200-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1223560 2017-05-07] (Ruiware)
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1223560 2017-05-07] (Ruiware)
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
R1 epp; C:\EEK\bin64\epp.sys [124552 2016-11-23] (Emsisoft Ltd)
S1 mbamchameleon; \??\C:\Windows\system32\drivers\mbamchameleon.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 VSScanner; system32\DRIVERS\vsscanner.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]
ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers4: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
Task: {2F74E8B2-69A2-4A0F-A3E5-9EBDFD44AD0D} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: {9514F30D-C8DA-4CB1-AB27-D743DD03904E} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
Task: {A432B3CF-C559-407B-9656-D8E9A2E12DBF} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1492466166-1735938548-1690570200-1000
Task: {AE5F3DE8-C9FB-47B7-AE5A-8B5B3259C90D} - System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: {EA935066-368B-4288-92AE-C3C9403B8386} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe
Task: C:\Windows\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}.job => C:\ProgramData\cis7D3A.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP😀1B5B4F1 [151]
MSCONFIG\Services: VoodooShieldService => 2
FirewallRules: [{8EA77410-6200-4326-96A9-2DC1FC8F8723}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{02D1563B-D869-4314-A7CF-3BFE79A9F8C0}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{E37B2E3D-BD7E-4D14-9C50-96028AAF46AD}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C8253294-4436-430C-B5EE-91193083C298}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C36A565E-B5A0-48B3-8973-F3559B6166A0}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{81CC9780-9D96-4C73-8ED4-A01A4676623F}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{F48882C1-0AD6-4DDD-A9C0-E213A7D9827A}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{54F0A311-72F9-49BD-8D81-291074F5556B}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{307BF65A-9757-43AB-858C-3B68ABB3E2A6}] => (Allow) C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{DF6A0D1D-5D57-4D6C-96B6-104AFBA3A8B2}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{24132901-D7BA-4A97-91FA-E60B7D31FB47}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{60E6D465-398E-4850-BE86-7EF7620A2377}] => (Block) C:\windows\system32\svchost.exe
C:\Program Files (x86)\Ruiware
C:\Program Files (x86)\MCShield
C:\Program Files\9-lab
C:\Users\Public\Desktop\Removal Tool.lnk
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool
C:\Program Files\COMODO
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state On


Restore point was successfully created.
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82} => value removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key removed successfully
HKU\S-1-5-21-1492466166-1735938548-1690570200-1000\Software\Microsoft\Windows\CurrentVersion\Run\\WinPatrol => value removed successfully
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\Software\Microsoft\Windows\CurrentVersion\Run\\WinPatrol => value removed successfully
HKU\S-1-5-21-1492466166-1735938548-1690570200-1001\Software\Microsoft\Windows\CurrentVersion\Run\\MCShield Monitor => value removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008 => key removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000009 => key removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000008 => key removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000009 => key removed successfully
HKLM\System\CurrentControlSet\Services\AppMgmt => key removed successfully
AppMgmt => service removed successfully
epp => Service stopped successfully.
HKLM\System\CurrentControlSet\Services\epp => key removed successfully
epp => service removed successfully
HKLM\System\CurrentControlSet\Services\mbamchameleon => key removed successfully
mbamchameleon => service removed successfully
HKLM\System\CurrentControlSet\Services\MBAMSwissArmy => key removed successfully
MBAMSwissArmy => service removed successfully
HKLM\System\CurrentControlSet\Services\VSScanner => key removed successfully
VSScanner => service removed successfully
HKLM\System\CurrentControlSet\Services\ZAM => key removed successfully
ZAM => service removed successfully
HKLM\System\CurrentControlSet\Services\ZAM_Guard => key removed successfully
ZAM_Guard => service removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Glary Utilities => key removed successfully
HKLM\Software\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} => key removed successfully
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\Glary Utilities => key removed successfully
HKLM\Software\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} => key not found.
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MSSE => key removed successfully
HKLM\Software\Classes\CLSID\{0365FE2C-F183-4091-AC82-BFC39FB75C49} => key not found.
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => key removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => key not found.
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Glary Utilities => key removed successfully
HKLM\Software\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} => key not found.
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => key removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{2F74E8B2-69A2-4A0F-A3E5-9EBDFD44AD0D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F74E8B2-69A2-4A0F-A3E5-9EBDFD44AD0D} => key removed successfully
C:\Windows\System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9514F30D-C8DA-4CB1-AB27-D743DD03904E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9514F30D-C8DA-4CB1-AB27-D743DD03904E} => key removed successfully
C:\Windows\System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A432B3CF-C559-407B-9656-D8E9A2E12DBF} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A432B3CF-C559-407B-9656-D8E9A2E12DBF} => key removed successfully
C:\Windows\System32\Tasks\Games\UpdateCheck_S-1-5-21-1492466166-1735938548-1690570200-1000 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Games\UpdateCheck_S-1-5-21-1492466166-1735938548-1690570200-1000 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AE5F3DE8-C9FB-47B7-AE5A-8B5B3259C90D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE5F3DE8-C9FB-47B7-AE5A-8B5B3259C90D} => key removed successfully
C:\Windows\System32\Tasks\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EA935066-368B-4288-92AE-C3C9403B8386} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA935066-368B-4288-92AE-C3C9403B8386} => key removed successfully
C:\Windows\System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => key removed successfully
C:\Windows\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}.job => moved successfully
"C:\ProgramData\TEMP" => "😀1B5B4F1" ADS not found.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\VoodooShieldService => key removed successfully
HKLM\System\CurrentControlSet\Services\VoodooShieldService => key not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8EA77410-6200-4326-96A9-2DC1FC8F8723} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{02D1563B-D869-4314-A7CF-3BFE79A9F8C0} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E37B2E3D-BD7E-4D14-9C50-96028AAF46AD} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C8253294-4436-430C-B5EE-91193083C298} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C36A565E-B5A0-48B3-8973-F3559B6166A0} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{81CC9780-9D96-4C73-8ED4-A01A4676623F} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F48882C1-0AD6-4DDD-A9C0-E213A7D9827A} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{54F0A311-72F9-49BD-8D81-291074F5556B} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{307BF65A-9757-43AB-858C-3B68ABB3E2A6} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DF6A0D1D-5D57-4D6C-96B6-104AFBA3A8B2} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{24132901-D7BA-4A97-91FA-E60B7D31FB47} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{60E6D465-398E-4850-BE86-7EF7620A2377} => value removed successfully
C:\Program Files (x86)\Ruiware => moved successfully
C:\ProgramData\cis7D3A.exe => moved successfully
"C:\Program Files (x86)\MCShield" => not found.
C:\EEK => moved successfully
"C:\Windows\system32\drivers\mbamchameleon.sys" => not found.
"C:\Windows\system32\drivers\MBAMSwissArmy.sys" => not found.
"C:\Windows\System32\drivers\zam64.sys" => not found.
"C:\Windows\System32\drivers\zamguard64.sys" => not found.
"C:\Windows\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82}.job" => not found.
C:\ProgramData\cmdres.dll => moved successfully
C:\Windows\system32\Drivers\4B53E2E4.sys => moved successfully
C:\ProgramData\Emsisoft => moved successfully
C:\Users\Owner\AppData\Roaming\9-lab => moved successfully
C:\Users\Patrick\AppData\Local\ESET => moved successfully
C:\Users\Owner\AppData\Local\ESET => moved successfully
C:\Program Files\9-lab => moved successfully
C:\Users\Public\Desktop\Removal Tool.lnk => moved successfully
C:\Users\Patrick\AppData\Roaming\9-lab => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\9-lab Removal Tool => moved successfully
C:\ProgramData\9-lab => moved successfully
C:\Users\Administrator\AppData\Local\Zemana => moved successfully
C:\Windows\ZAM.krnl.trace => moved successfully
C:\Windows\ZAM_Guard.krnl.trace => moved successfully
C:\ProgramData\HitmanPro => moved successfully
"C:\ProgramData\cis7D3A.exe" => not found.
C:\Program Files\COMODO => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= netsh advfirewall reset =========

Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003

An error occurred while attempting to contact the Windows Firewall service. Make sure that the service is running and try your request again.

========= End of CMD: =========

========= netsh advfirewall set allprofiles state On =========

Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 11003

An error occurred while attempting to contact the Windows Firewall service. Make sure that the service is running and try your request again.

========= End of CMD: =========

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 2100493 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Patrick => 23707807 B
Owner => 5411 B
Administrator => 432 B

RecycleBin => 0 B
EmptyTemp: => 24.6 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 15:06:50 ====
Hi PatL, Please run this ZHP fix.

Please go HERE and click the blue
link (French for download) and save the file to your desktop.

Please note is it important to disable your antivirus before running this tool. If you are uncertain how to do this please ask?

Right click the desktop icon
and choose "Run as Administrator". You can safely ignore any security warnings when running this tool.

On the main interface select IMPORT


If a box appears similar to that below, click OK or just X out of it.


Copy the contents of the box below

Script Zhpfix
O38 - TASK: {2F74E8B2-69A2-4A0F-A3E5-9EBDFD44AD0D} [64Bits][\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {39A98B3C-C528-4993-8E16-3399E7A62867} [64Bits][\Microsoft\Windows\Media Center\mcupdate] - (...) -- C:\Windows\ehome\mcupdate (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {3B3DCCBA-789E-4662-A0AF-49E6D2F4BCF7} [64Bits][\Microsoft\Windows\Media Center\StartRecording] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {9514F30D-C8DA-4CB1-AB27-D743DD03904E} [64Bits][\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {999DA5BD-5583-4F14-97FA-1602A926540D} [64Bits][\Microsoft\Windows\Media Center\RecordingRestart] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {AE5F3DE8-C9FB-47B7-AE5A-8B5B3259C90D} [64Bits][\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O38 - TASK: {EA935066-368B-4288-92AE-C3C9403B8386} [64Bits][\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.) =>.SUP.Orphan
O10 - WLSP:\NameSpace_Catalog5\Catalog_Entries\000000000008\Winsock LSP File . (...) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Not File) =>Hijacker.Winsock
O10 - WLSP:\NameSpace_Catalog5\Catalog_Entries\000000000009\Winsock LSP File . (...) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Not File) =>Hijacker.Winsock
O10 - WLSP:\NameSpace_Catalog5\Catalog_Entries64\000000000008\Winsock LSP File . (...) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Not File) =>Hijacker.Winsock
O10 - WLSP:\NameSpace_Catalog5\Catalog_Entries64\000000000009\Winsock LSP File . (...) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Not File) =>Hijacker.Winsock
O108 - CMH1: Glary Utilities [64Bits] - {B3C418F8-922B-4faf-915E-59BC14448CF7} . (.Orphan.)
O108 - CMH4: MSSE [64Bits] - {0365FE2C-F183-4091-AC82-BFC39FB75C49} . (.Orphan.)
O108 - CMH4: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Orphan.)
O108 - CMH6: Glary Utilities [64Bits] - {B3C418F8-922B-4faf-915E-59BC14448CF7} . (.Orphan.)
O108 - CMH6: Offline Files [64Bits] - {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} . (.Orphan.)
O108 - CMH7: Glary Utilities [64Bits] - {B3C418F8-922B-4faf-915E-59BC14448CF7} . (.Orphan.)
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\Glary Utilities =>.SUP.Orphan
HKLM\Software\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} =>.SUP.Orphan
HKLM\Software\Wow6432Node\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7} =>.SUP.Orphan
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MSSE =>.SUP.Orphan
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Glary Utilities =>.SUP.Orphan
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files =>.SUP.Orphan
HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\Glary Utilities =>.SUP.Orphan
And paste it into the blank ZHP Fix interface screen, then click GO.


Accept the cleaning process by clicking "Oui" (yes)


The cleanup will run and will again ask for permission to complete, again select "Oui".

At the conclusion of cleaning a file notepad will open and be saved to your desktop. Please Copy and Paste the contents of this file in your next reply🙂
Rapport de ZHPFix 2017.06.13.1 par Nicolas Coolman, Update du 13/06/2017
Fichier d'export Registre :
Run by Patrick at 11/25/2017 5:36:29 PM
High Elevated Privileges : OK
Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)

Recycle Bin emptied (01mn AMs)

========== Registry keys ==========
REMOVES: HKLM\Software\Wow6432Node\Classes\CLSID\{B3C418F8-922B-4faf-915E-59BC14448CF7}

========== Folders ==========
No folders empty CLSID Local user

========== Files ==========
Deletes temporary Windows (0) (0 octets)

========== Other ==========
NON-TREATY O38 - TASK: {2F74E8B2-69A2-4A0F-A3E5-9EBDFD44AD0D} [64Bits][\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.)
NON-TREATY O38 - TASK: {39A98B3C-C528-4993-8E16-3399E7A62867} [64Bits][\Microsoft\Windows\Media Center\mcupdate] - (...) -- C:\Windows\ehome\mcupdate (.not file.) [0] (.Orphan.)
NON-TREATY O38 - TASK: {3B3DCCBA-789E-4662-A0AF-49E6D2F4BCF7} [64Bits][\Microsoft\Windows\Media Center\StartRecording] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.)
NON-TREATY O38 - TASK: {9514F30D-C8DA-4CB1-AB27-D743DD03904E} [64Bits][\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (.not file.) [0] (.Orphan.)
NON-TREATY O38 - TASK: {999DA5BD-5583-4F14-97FA-1602A926540D} [64Bits][\Microsoft\Windows\Media Center\RecordingRestart] - (...) -- C:\Windows\ehome\ehrec (.not file.) [0] (.Orphan.)
NON-TREATY O38 - TASK: {AE5F3DE8-C9FB-47B7-AE5A-8B5B3259C90D} [64Bits][\COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.)
NON-TREATY O38 - TASK: {EA935066-368B-4288-92AE-C3C9403B8386} [64Bits][\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}] - (...) -- C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe (.not file.) [0] (.Orphan.)

========== Summary ==========
1 : Registry keys
1 : Folders
1 : Files
7 : Other

End of clean in 02mn AMs

========== Path to file report ==========
C:\Users\Patrick\AppData\Roaming\ZHP\ZHPFix[R1].txt - 11/19/2017 10:23:18 AM [1571]
C:\Users\Patrick\AppData\Roaming\ZHP\ZHPFix[R2].txt - 11/19/2017 1:25:56 PM [637]
C:\Users\Patrick\AppData\Roaming\ZHP\ZHPFix[R3].txt - 11/19/2017 1:26:09 PM [800]
C:\Users\Patrick\AppData\Roaming\ZHP\ZHPFix[R4].txt - 11/25/2017 5:36:30 PM [2487]
There are no changes and the issues from before still remain. While in Normal Mode under my Standard User Account: Owner anything I click that is in the taskbar gives me the window: "Can't open this item: it might have been moved, renamed, or deleted." Also any shortcuts on the desktop I click and anything in the start menu clicked on do not open. I have to manually move to the folder where the program I am trying to open is, then double click it.
From the amount of Security apps removed in this thread, which you have obviously used with unknown results, and the scans we have performed there is little evidence of any remaining malware. Therefore it would appear that there are issues with Windows 7 itself.

Before I move this thread out of malware can you try?

Run system File Checker
creating another account and see if the issues remain?
I've tested the problem on my Patrick account, it does not occur. Also on the effected account the problem vanishes in Safe Mode. It's quite frustrating... SFC did not find any integrity violations.
I've tested the problem on my Patrick account, it does not occur.

Voila, why not use your Patrick (admin) account?

Shall move this thread to Windows 7 forum.

EDIT: these are the accounts listed from the supplied logs

Administrator (S-1-5-21-1492466166-1735938548-1690570200-500 - Administrator - Disabled) => C:\Users\Administrator
Guest (S-1-5-21-1492466166-1735938548-1690570200-501 - Limited - Disabled)
Owner (S-1-5-21-1492466166-1735938548-1690570200-1001 - Limited - Enabled) => C:\Users\Owner
Patrick (S-1-5-21-1492466166-1735938548-1690570200-1000 - Administrator - Enabled) => C:\Users\Patrick
Last edited:
