Sorry didn't read all!
Pasted here is: FRST.TXT
----------------------------
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13.02.2019
Ran by Robert (administrator) on MAIN (13-02-2019 12:41:46)
Running from C:\Users\Robert\Desktop
Loaded Profiles: Robert (Available Profiles: Robert & Administrator)
Platform: Windows 10 Pro Version 1809 17763.253 (X64) Language: English (United States)
Default browser: "C:\Program Files\Waterfox\waterfox.exe" -osint -url "%1"
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidMonitorSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Backblaze\bzserv.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
() C:\Program Files (x86)\NordVPN\nordvpn-service.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Windows\System32\snmp.exe
() C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
(Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PrecisionX_x64.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(Bitsum LLC) C:\Program Files\Process Lasso\ProcessGovernor.exe
(Bitsum LLC) C:\Program Files\Process Lasso\ProcessLasso.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PrecisionXServer.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PXSW10_x64.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(GP Software) C:\Program Files\Directory Opus\dopusrt.exe
() C:\Program Files (x86)\Backblaze\bzbui.exe
(NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe
(Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Program Files (x86)\AudioSwitch\AudioSwitch.exe
() C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(XRayz Software) C:\Program Files\ClipCache\clipc.exe
(Code Sector) C:\Program Files (x86)\Direct Folders\df.exe
(Code Sector Inc.) C:\Program Files (x86)\Direct Folders\df64.exe
(Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSATray.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\natspeak.exe
(Neuber Software - www.neuber.com) C:\Program Files (x86)\Security Task Manager\SpyProtector.exe
(Carthago Software) C:\Program Files (x86)\MemInfo\meminfo.exe
() C:\Program Files (x86)\CyberPower PowerPanel Personal\PowerPanel Personal.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Sync.com Inc.) C:\Users\Robert\AppData\Local\Programs\Sync\sync-taskbar.exe
() C:\Users\Robert\AppData\Local\Programs\Sync\sync-worker.exe
() C:\Users\Robert\AppData\Local\Programs\Sync\sync-worker.exe
() C:\Users\Robert\AppData\Local\Programs\Sync\sync-worker.exe
(NTWind Software) C:\Program Files\WindowSpace\wspace64.exe
(NTWind Software) C:\Program Files\WindowSpace\wspace32.exe
(Microsoft Corporation) C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking15\x64\dgnuiasvr_x64.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking15\dragonbar.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
() C:\Program Files (x86)\CyberPower PowerPanel Personal\ppped.exe
() C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Safer-Networking Ltd\Spybot Anti-Beacon\Spybot3AntiBeacon.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(WordWeb Software) C:\Program Files (x86)\WordWeb\wweb32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
() C:\Program Files\Everything\Everything.exe
(Ipswitch, Inc. 83 Hartwell Avenue Lexington, MA 02421) C:\Program Files (x86)\Ipswitch\WS_FTP 12\WsftpCOMHelper.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\ecmds.exe [177928 2019-01-03] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2675176 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
HKLM\...\Run: [IAStorIcon] => c:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321096 2017-06-20] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279520 2019-01-31] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-07-06] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [Fences] => C:\Program Files (x86)\Stardock\Fences\Fences.exe [4854200 2018-05-25] (Stardock Corporation -> Stardock Corporation) [File not signed]
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [588360 2017-06-22] (Acronis International GmbH -> )
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5118656 2017-06-22] (Acronis International GmbH -> )
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [137464 2018-07-30] (Intel(R) Driver & Support Assistant -> Intel)
HKLM-x32\...\Run: [Spy Protector] => C:\Program Files (x86)\Security Task Manager\SpyProtector.exe [145280 2018-07-12] (A. & M. Neuber Software -> Neuber Software - www.neuber.com)
HKLM-x32\...\Run: [WordWeb] => C:\Program Files (x86)\WordWeb\wweb32.exe [81120 2016-02-12] (WordWeb Software -> WordWeb Software)
HKLM-x32\...\Run: [CyberPower] => C:\Program Files (x86)\CyberPower PowerPanel Personal\PowerPanel Personal.exe [123392 2018-07-17] () [File not signed]
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [125872 2018-11-21] (VMware, Inc. -> VMware, Inc.)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2075480 2013-06-24] (Flexera Software LLC -> Flexera Software LLC.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [4810224 2018-12-19] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM\...\Policies\Explorer: [ForceActiveDesktopOn] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\...\Policies\Explorer: [NoRecentDocsHistory] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\...\Policies\Explorer: [NoChangeStartMenu] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\...\Policies\Explorer: [NoControlPanel] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2018-09-14] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2018-09-14] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [Directory Opus Desktop Dblclk] => C:\Program Files\Directory Opus\dopusrt.exe [694128 2017-06-09] (GP Software -> GP Software)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [1061728 2019-02-07] (Backblaze, Inc -> )
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [2222032 2018-12-04] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19645800 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2075480 2013-06-24] (Flexera Software LLC -> Flexera Software LLC.)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [Fences] => c:\program files (x86)\stardock\fences\Fences.exe [4854200 2018-05-25] (Stardock Corporation -> Stardock Corporation)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [HomeAlarm] => C:\Program Files (x86)\Chameleon Clock\ChamClock.exe [709632 2007-12-11] (Softshape Development)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoPreviewPane] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [HideSCANetwork] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [HideSCAVolume] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [DisableThumbnails] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoFileMenu] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoToolbarCustomize] 1
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-18\...\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [1061728 2019-02-07] (Backblaze, Inc -> )
HKLM\...\Drivers32-x32: [vidc.tscc] => C:\Windows\SysWOW64\tsccvid.dll [102400 2005-06-15] (TechSmith Corporation)
HKLM\...\Drivers32-x32: [msacm.pspgru] => C:\Windows\SysWOW64\pspgru.acm [401920 2010-03-22] (Philips Austria GmbH - Speech Processing)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.96\Installer\chrmstp.exe [2019-02-07] (Google LLC -> Google Inc.)
Lsa: [Authentication Packages] msv1_0 SshdPinAuthLsa
ShellExecuteHooks: Directory Opus Shell Execute Hook - {3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} - C:\Program Files\Directory Opus\dopuslib.dll [765808 2017-06-09] (GP Software -> GP Software)
ShellExecuteHooks-x32: Directory Opus Shell Execute Hook - {EE761688-C137-4b04-8FAB-3C9CDF0886F0} - C:\Program Files\Directory Opus\dopuslib32.dll [381296 2017-06-09] (GP Software -> GP Software)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AudioSwitch.lnk [2018-10-16]
ShortcutTarget: AudioSwitch.lnk -> C:\Program Files (x86)\AudioSwitch\AudioSwitch.exe ()
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ClipCache Pro.lnk [2019-01-10]
ShortcutTarget: ClipCache Pro.lnk -> C:\Program Files\ClipCache\clipc.exe (XRayz Software)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Direct Folders.lnk [2018-10-18]
ShortcutTarget: Direct Folders.lnk -> C:\Program Files (x86)\Direct Folders\df.exe (Code Sector)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dragon NaturallySpeaking.lnk [2018-11-04]
ShortcutTarget: Dragon NaturallySpeaking.lnk -> C:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\natspeak.exe (Nuance Communications, Inc.)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\meminfo.lnk [2018-10-16]
ShortcutTarget: meminfo.lnk -> C:\Program Files (x86)\MemInfo\meminfo.exe (Carthago Software)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\schedhlp.lnk [2018-10-16]
ShortcutTarget: schedhlp.lnk -> C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe ()
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar551.lnk [2019-02-12]
ShortcutTarget: Sidebar551.lnk -> C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sync.lnk [2019-01-12]
ShortcutTarget: Sync.lnk -> C:\Users\Robert\AppData\Local\Programs\Sync\sync-taskbar.exe (Sync.com Inc.)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wspace64.lnk [2018-10-16]
ShortcutTarget: wspace64.lnk -> C:\Program Files\WindowSpace\wspace64.exe (NTWind Software)
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\.DEFAULT\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-2536635842-542287166-2959069790-1002\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{088debab-fa3f-4522-be18-eed74e83a81a}: [NameServer] 1.1.1.1,1.0.0.1
Tcpip\..\Interfaces\{088debab-fa3f-4522-be18-eed74e83a81a}: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{2643f73e-6fcf-49ed-b1c0-243ab565a6d6}: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{65450657-b491-4d43-ac56-02632efc959c}: [DhcpNameServer] 208.67.222.222 208.67.220.220
Internet Explorer:
==================
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO: No Name -> {27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5} -> M:\__NEW SYSTEM\OldNewExplorer\OldNewExplorer64.dll [2017-08-16] (www.startisback.com)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
BHO: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> c:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\x64\dgnriaie_x64.dll [2018-01-27] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_191\bin\ssv.dll [2018-10-30] ()
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-10-30] ()
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> No File
BHO-x32: No Name -> {27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5} -> M:\__NEW SYSTEM\OldNewExplorer\OldNewExplorer32.dll [2017-08-16] (www.startisback.com)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
BHO-x32: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> c:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\dgnriaie.dll [2018-01-27] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\ssv.dll [2018-10-30] ()
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-10-30] ()
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> No File
Toolbar: HKLM - TextAloud Toolbar - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Program Files (x86)\TextAloud\TAForIE64.dll [2017-07-24] (NEXTUP TECHNOLOGIES, LLC -> NextUp.com)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - TextAloud Toolbar - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Program Files (x86)\TextAloud\TAForIE.dll [2017-07-24] (NEXTUP TECHNOLOGIES, LLC -> NextUp.com)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
IE Session Restore: HKU\S-1-5-21-2536635842-542287166-2959069790-1002 -> is enabled.
Handler-x32: intu-help-qb7 - {5A03BD9D-766D-47A6-8E87-CD90F60BE245} - C:\Program Files (x86)\Intuit\QuickBooks 2014\HelpAsyncPluggableProtocol.dll [2014-12-10] (Intuit, Inc. -> Intuit, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll [2018-09-14] (Microsoft Windows -> Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File
Edge:
======
Edge Extension: (Adblock Plus) -> 10_EyeoGmbHAdblockPlus_d55gg7py3s0m0 => C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.9.0_neutral__d55gg7py3s0m0 [2019-01-16]
Edge Extension: (Ghostery – Privacy Ad Blocker) -> EdgeExtension_GhosteryGhostery_kzkqe0pn505dg => C:\Program Files\WindowsApps\Ghostery.Ghostery_8.1.0.0_neutral__kzkqe0pn505dg [2019-01-16]
FireFox:
========
FF DefaultProfile: m2jh29d5.default
FF DefaultProfile: 01gmxgwq.Normal
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Thinstall\RegCleanPro\%AppData%\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 [not found] <==== ATTENTION
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Thinstall\RegCleanPro\%AppData%\Mozilla\Firefox\Profiles\01gmxgwq.Normal [not found] <==== ATTENTION
FF DefaultProfile: i4a2hsup.Default-1504416014746
FF DefaultProfile: qnjlgicb.default
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default [2019-02-13]
FF Homepage: Waterfox\Profiles\m2jh29d5.default -> hxxps://www.startpage.com/
FF NewTab: Waterfox\Profiles\m2jh29d5.default -> www.startpage.com
FF Session Restore: Waterfox\Profiles\m2jh29d5.default -> is enabled.
FF Extension: (Amazon Assistant for Firefox) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\abb@amazon.com.xpi [2018-05-09]
FF Extension: (AIO Search) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\ASToolbar@aiosearch.com.xpi [2018-01-22]
FF Extension: (New Add-on Bar) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\ausaddonbar@teo.pl.xpi [2018-11-04] [Legacy]
FF Extension: (Bookmarks Favicon Images) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\BookmarksFaviconImages@LarrysComputer.xpi [2018-11-03] [Legacy]
FF Extension: (Bookmarks Folder Images) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\BookmarksFolderImages@LarrysComputer.xpi [2018-10-06] [Legacy]
FF Extension: (Bookmarks Title Styles) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\BookmarksTitleStyles@LarrysComputer.xpi [2018-11-03] [Legacy]
FF Extension: (Classic Reload-Stop-Go Button) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\crsg@ArisT2_Noia4dev.xpi [2018-11-03] [Legacy]
FF Extension: (Classic Toolbar Buttons) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2018-07-06] [Legacy]
FF Extension: (Dragon Professional Web Extension) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\dgnria_pro.firefox@nuance.com.xpi [2018-10-08]
FF Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\firefox@ghostery.com.xpi [2019-02-01]
FF Extension: (SimilarWeb - Traffic Rank & Website Analysis) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\FirefoxAddon@similarWeb.com.xpi [2018-11-03]
FF Extension: (Webmail Ad Blocker) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\gmailnoads@mywebber.com.xpi [2019-01-03]
FF Extension: (Who stole my pictures?) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\images@wink.su.xpi [2018-04-02]
FF Extension: (PriceBlink Coupons and Price Comparison) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\info@priceblink.com.xpi [2019-01-25]
FF Extension: (Terms of Service; Didn’t Read) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid0-3GUEt1r69sQNSrca5p8kx9Ezc3U@jetpack.xpi [2018-08-20]
FF Extension: (Visited) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid0-xGZYdxpAkROWMUMfWKINyrXigBA@jetpack.xpi [2018-01-27] [Legacy]
FF Extension: (YouTube™ Flash® Player) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi [2018-10-03]
FF Extension: (Media Converter and Muxer) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid1-kps5PrGBNtzSLQ@jetpack.xpi [2018-02-12] [Legacy]
FF Extension: (Privacy Badger) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2018-09-20]
FF Extension: (Free Memory) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid1-n85lxPv1NAWVTQ@jetpack.xpi [2018-11-17] [Legacy]
FF Extension: (Lightweight Themes Manager) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\lwthemes-manager@loucypher.xpi [2018-10-03] [Legacy]
FF Extension: (Memory Restart) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\memoryrestart@teamextension.com.xpi [2018-11-17] [Legacy]
FF Extension: (Menu Icons Plus) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\menuiconsplus@codedawn.com.xpi [2018-05-07] [Legacy]
FF Extension: (Saved Password Editor) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\savedpasswordeditor@daniel.dawson.xpi [2018-11-03] [Legacy]
FF Extension: (Tab Session Manager) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\Tab-Session-Manager@sienori.xpi [2019-02-08]
FF Extension: (The Addon Bar (restored)) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\the-addon-bar@GeekInTraining-GiT.xpi [2018-11-03] [Legacy]
FF Extension: (TinEye Reverse Image Search) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\tineye@ideeinc.com.xpi [2018-10-04]
FF Extension: (TrackMeNot) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\trackmenot@mrl.nyu.edu.xpi [2018-11-03]
FF Extension: (uBlock Origin) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\uBlock0@raymondhill.net.xpi [2019-02-05]
FF Extension: (uMatrix) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\uMatrix@raymondhill.net.xpi [2019-01-03]
FF Extension: (Vertical Toolbar) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\verticaltoolbar@xuldev.org.xpi [2018-11-03] [Legacy]
FF Extension: (Session Manager) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2018-11-03] [Legacy]
FF Extension: (Multirow Bookmarks Toolbar Plus) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{4c7097f7-08f2-4ef2-9b9f-f95fa4cbb064}.xpi [2018-05-19] [Legacy]
FF Extension: (No Coin - Block miners on the web!) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{5657c026-efc3-4860-b43b-16e4eaa8a9aa}.xpi [2019-01-24]
FF Extension: (Google™ Shortcuts - MSG_cj_i18n_01720) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2019-02-12]
FF Extension: (Download Status Bar) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2018-09-08] [Legacy]
FF Extension: (Bulk Media Downloader) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{72b2e02b-3a71-4895-886c-fd12ebe36ba3}.xpi [2018-02-12]
FF Extension: (blockcoinm) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{74b0af75-8791-44e2-95a6-7f0ab94143ec}.xpi [2019-01-26]
FF Extension: (Download Statusbar) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{76faaba6-3aa1-47a4-bf40-90aa2505e79c}.xpi [2019-01-03]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2019-01-26]
FF Extension: (Video DownloadHelper) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2018-01-22]
FF Extension: (In My Pocket) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{cd7e22de-2e34-40f0-aeff-cec824cbccac}.xpi [2019-01-03]
FF Extension: (OFFMP4 - Best Video Download Helper) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{cf9bb404-04a5-4329-8764-aae71359f0f8}.xpi [2019-01-22]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-01-23]
FF Extension: (Tab Mix Plus) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2018-09-05] [Legacy]
FF Extension: (SnapTube MP3 for YouTube Music Download) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{e4b3d1b4-3bb2-4df7-ad1b-77534bac5780}.xpi [2018-12-01]
FF Extension: (YouTube Flash Video Player) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2018-05-06]
FF Extension: (Theme Font & Size Changer) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{f69e22c7-bc50-414a-9269-0f5c344cd94c}.xpi [2018-11-03]
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 [2019-02-11]
FF user.js: detected! => C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\user.js [2018-11-03]
FF Homepage: Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 -> hxxps://www.startpage.com/
FF NewTab: Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 -> www.startpage.com
FF NetworkProxy: Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 -> type", 0
FF Session Restore: Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 -> is enabled.
FF Extension: (Amazon Assistant for Firefox) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\abb@amazon.com.xpi [2018-05-09]
FF Extension: (AIO Search) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\ASToolbar@aiosearch.com.xpi [2018-01-22]
FF Extension: (New Add-on Bar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\ausaddonbar@teo.pl.xpi [2018-11-04] [Legacy]
FF Extension: (Bookmarks Favicon Images) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\BookmarksFaviconImages@LarrysComputer.xpi [2018-11-04] [Legacy]
FF Extension: (Bookmarks Folder Images) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\BookmarksFolderImages@LarrysComputer.xpi [2018-10-06] [Legacy]
FF Extension: (Bookmarks Title Styles) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\BookmarksTitleStyles@LarrysComputer.xpi [2018-11-04] [Legacy]
FF Extension: (Classic Toolbar Buttons) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2018-07-06] [Legacy]
FF Extension: (Dragon Professional Web Extension) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\dgnria_pro.firefox@nuance.com.xpi [2018-10-08]
FF Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\firefox@ghostery.com.xpi [2019-02-05]
FF Extension: (Webmail Ad Blocker) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\gmailnoads@mywebber.com.xpi [2019-01-13]
FF Extension: (Who stole my pictures?) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\images@wink.su.xpi [2018-04-02]
FF Extension: (PriceBlink Coupons and Price Comparison) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\info@priceblink.com.xpi [2019-01-26]
FF Extension: (Terms of Service; Didn’t Read) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid0-3GUEt1r69sQNSrca5p8kx9Ezc3U@jetpack.xpi [2018-08-20]
FF Extension: (Visited) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid0-xGZYdxpAkROWMUMfWKINyrXigBA@jetpack.xpi [2018-01-27] [Legacy]
FF Extension: (YouTube™ Flash® Player) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi [2018-10-03]
FF Extension: (Media Converter and Muxer) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid1-kps5PrGBNtzSLQ@jetpack.xpi [2018-02-12] [Legacy]
FF Extension: (Privacy Badger) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2019-02-10]
FF Extension: (Free Memory) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid1-n85lxPv1NAWVTQ@jetpack.xpi [2018-11-18] [Legacy]
FF Extension: (Lightweight Themes Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\lwthemes-manager@loucypher.xpi [2018-10-03] [Legacy]
FF Extension: (Menu Icons Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\menuiconsplus@codedawn.com.xpi [2018-05-07] [Legacy]
FF Extension: (Tab Session Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\Tab-Session-Manager@sienori.xpi [2019-02-09]
FF Extension: (TinEye Reverse Image Search) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\tineye@ideeinc.com.xpi [2018-10-04]
FF Extension: (uBlock Origin) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\uBlock0@raymondhill.net.xpi [2019-02-05]
FF Extension: (uMatrix) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\uMatrix@raymondhill.net.xpi [2019-01-13]
FF Extension: (Session Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2018-11-04] [Legacy]
FF Extension: (Multirow Bookmarks Toolbar Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{4c7097f7-08f2-4ef2-9b9f-f95fa4cbb064}.xpi [2018-05-19] [Legacy]
FF Extension: (No Coin - Block miners on the web!) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{5657c026-efc3-4860-b43b-16e4eaa8a9aa}.xpi [2019-01-26]
FF Extension: (Google™ Shortcuts - All services at a glance) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2019-01-31]
FF Extension: (Download Status Bar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2018-09-08] [Legacy]
FF Extension: (Bulk Media Downloader) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{72b2e02b-3a71-4895-886c-fd12ebe36ba3}.xpi [2018-02-12]
FF Extension: (blockcoinm) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{74b0af75-8791-44e2-95a6-7f0ab94143ec}.xpi [2019-01-26]
FF Extension: (Download Statusbar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{76faaba6-3aa1-47a4-bf40-90aa2505e79c}.xpi [2019-01-13]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2019-01-26]
FF Extension: (Video DownloadHelper) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2018-01-22]
FF Extension: (In My Pocket) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{cd7e22de-2e34-40f0-aeff-cec824cbccac}.xpi [2019-01-13]
FF Extension: (OFFMP4 - Best Video Download Helper) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{cf9bb404-04a5-4329-8764-aae71359f0f8}.xpi [2019-01-26]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-01-26]
FF Extension: (Tab Mix Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2018-09-05] [Legacy]
FF Extension: (SnapTube MP3 for YouTube Music Download) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{e4b3d1b4-3bb2-4df7-ad1b-77534bac5780}.xpi [2018-12-01]
FF Extension: (YouTube Flash Video Player) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2018-05-06]
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal [2019-02-11]
FF user.js: detected! => C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\user.js [2018-11-03]
FF Homepage: Mozilla\Firefox\Profiles\01gmxgwq.Normal -> hxxp://www.google.com/
FF NewTab: Mozilla\Firefox\Profiles\01gmxgwq.Normal -> hxxp://www.google.com
FF NetworkProxy: Mozilla\Firefox\Profiles\01gmxgwq.Normal -> type", 4
FF Session Restore: Mozilla\Firefox\Profiles\01gmxgwq.Normal -> is enabled.
FF Extension: (Grammarly for Firefox) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\87677a2c52b84ad3a151a4a72f5bd3c4@jetpack.xpi [2017-12-24]
FF Extension: (HLS Stream Detector) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\@m3u8link.xpi [2017-09-21] [Legacy]
FF Extension: (AIO Search) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\ASToolbar@aiosearch.com.xpi [2017-08-19]
FF Extension: (New Add-on Bar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\ausaddonbar@teo.pl.xpi [2017-08-17] [Legacy]
FF Extension: (Bookmarks Favicon Images) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\BookmarksFaviconImages@LarrysComputer.xpi [2017-11-15] [Legacy]
FF Extension: (Bookmarks Title Styles) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\BookmarksTitleStyles@LarrysComputer.xpi [2017-11-15] [Legacy]
FF Extension: (Add-on Compatibility Reporter) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\compatibility@addons.mozilla.org.xpi [2017-07-18] [Legacy]
FF Extension: (Classic Reload-Stop-Go Button) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\crsg@ArisT2_Noia4dev.xpi [2017-09-17] [Legacy]
FF Extension: (Classic Toolbar Buttons) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2017-12-24] [Legacy]
FF Extension: (Dragon Web Extension) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\dgnria2@nuance.com.xpi [2017-12-09] [Legacy]
FF Extension: (Exif Viewer) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\exif_viewer@mozilla.doslash.org.xpi [2017-12-30]
FF Extension: (Ghostery) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\firefox@ghostery.com.xpi [2017-12-30]
FF Extension: (SimilarWeb - Traffic Rank & Website Analysis) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\FirefoxAddon@similarWeb.com.xpi [2017-12-24]
FF Extension: (Webmail Ad Blocker) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\gmailnoads@mywebber.com.xpi [2017-12-24]
FF Extension: (PriceBlink Coupons and Price Comparison) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\info@priceblink.com.xpi [2017-11-16]
FF Extension: (Turbo Download Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid0-dsq67mf5kjjhiiju2dfb6kk8dfw@jetpack.xpi [2017-02-28] [Legacy]
FF Extension: (Media Converter and Muxer) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid1-kps5PrGBNtzSLQ@jetpack.xpi [2017-05-30] [Legacy]
FF Extension: (Privacy Badger) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2017-12-24]
FF Extension: (igshortcuts) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid1-SVJwkBGCTt4PyQ@jetpack.xpi [2017-08-21]
FF Extension: (visited_enabler) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid1-yDnsmkBoiRtgNA@jetpack.xpi [2017-07-06] [Legacy]
FF Extension: (Master Password+) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\masterpasswordtimeoutplus@vano [2018-01-14] [Legacy]
FF Extension: (Saved Password Editor) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\savedpasswordeditor@daniel.dawson.xpi [2017-11-16] [Legacy]
FF Extension: (StickyNotes) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\sticky@filenamezero.dip.jp.xpi [2017-12-30]
FF Extension: (TinEye Reverse Image Search) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\tineye@ideeinc.com.xpi [2017-06-28]
FF Extension: (TrackMeNot) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\trackmenot@mrl.nyu.edu.xpi [2017-12-24]
FF Extension: (uBlock Origin) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\uBlock0@raymondhill.net.xpi [2017-12-24]
FF Extension: (uMatrix) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\uMatrix@raymondhill.net.xpi [2017-12-24]
FF Extension: (Vertical Toolbar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\verticaltoolbar@xuldev.org.xpi [2017-11-16] [Legacy]
FF Extension: (Flagfox) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2017-11-16] [Legacy]
FF Extension: (Session Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2017-11-15] [Legacy]
FF Extension: (Extension Options Menu) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{1feca320-6b4d-11df-a08a-0800200c9a66}.xpi [2017-09-02] [Legacy]
FF Extension: (Multirow Bookmarks Toolbar Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{4c7097f7-08f2-4ef2-9b9f-f95fa4cbb064}.xpi [2017-09-07] [Legacy]
FF Extension: (EPUBReader) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}.xpi [2017-08-01]
FF Extension: (Google™ Shortcuts - All services at a glance) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2017-12-24]
FF Extension: (Download Status Bar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2017-11-15] [Legacy]
FF Extension: (Bulk Media Downloader) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{72b2e02b-3a71-4895-886c-fd12ebe36ba3}.xpi [2017-11-16]
FF Extension: (Themes Menu) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi [2017-05-31] [Legacy]
FF Extension: (More Tools Menu) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{9a7a67d3-3048-47fb-acde-d0f7ae51f86a}.xpi [2017-07-19] [Legacy]
FF Extension: (Video DownloadHelper) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-11-15]
FF Extension: (Adblock Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-01-22]
FF Extension: (Tab Mix Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2017-11-15] [Legacy]
FF Extension: (Theme Font & Size Changer) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{f69e22c7-bc50-414a-9269-0f5c344cd94c}.xpi [2017-11-15]
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default [2018-06-09]
FF Extension: (Czech (CZ) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-cs@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Deutsch (DE) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-de@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (English (US) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-en-US@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Español (España) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-es-ES@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Finnish Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-fi@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Français Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-fr@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Galego (España) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-gl@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Hebrew (IL) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-he@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Magyar (HU) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-hu@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Italiano (IT) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-it@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Japanese Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-ja@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Korean (KR) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-ko@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Nederlands (NL) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-nl@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Polski Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-pl@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Russian (RU) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-ru@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Slovenski jezik Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-sl@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (српски (sr) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-sr@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Svenska (SE) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-sv-SE@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Chinese Simplified (zh-CN) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-zh-CN@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Traditional Chinese (zh-TW) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-zh-TW@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF HKLM\...\Firefox\Extensions: [{5e1bc830-4746-11e5-b970-0800200c9a66}] - C:\Program Files (x86)\TextAloud\TAForFirefox.xpi
FF Extension: (TextAloud for Firefox) - C:\Program Files (x86)\TextAloud\TAForFirefox.xpi [2018-03-04]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2018-10-19]
FF HKLM-x32\...\Firefox\Extensions: [{5e1bc830-4746-11e5-b970-0800200c9a66}] - C:\Program Files (x86)\TextAloud\TAForFirefox.xpi
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_114.dll [2019-01-11] ()
FF Plugin: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-10-30] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-10-30] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-01-24] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-25] (Adobe Systems)
FF Plugin: nuance.com/DgnRia2_x86_64 -> c:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\x64\npDgnRia2_x64.dll [2018-01-27] (Nuance Communications, Inc.)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_114.dll [2019-01-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-10-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-10-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2019-01-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2019-01-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2019-01-11] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-01-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-01-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2018-12-19] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-25] (Adobe Systems)
FF Plugin-x32: nuance.com/DgnRia2 -> c:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\npDgnRia2.dll [2018-01-27] (Nuance Communications, Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default [2019-01-30]
CHR Extension: (Slides) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-14]
CHR Extension: (Docs) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-14]
CHR Extension: (Google Drive) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-14]
CHR Extension: (YouTube) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-14]
CHR Extension: (uBlock Origin) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2018-08-28]
CHR Extension: (Sheets) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-14]
CHR Extension: (Google Docs Offline) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-08-28]
CHR Extension: (TextAloud for Chrome) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\obcnimnkkpdkbfnnoagjogdollcfnidj [2018-08-28]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-08-28]
CHR Extension: (Gmail) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-14]
CHR Extension: (Chrome Media Router) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-19]
CHR Profile: C:\Users\Robert\AppData\Local\Google\Chrome\User Data\System Profile [2018-10-06]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [obcnimnkkpdkbfnnoagjogdollcfnidj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-25] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2917864 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2709480 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
S3 AndServMgr; c:\Program Files\AMI\DuOS\AndServMgr.exe [86944 2018-03-07] (American Megatrends Inc -> American Megatrends Inc.)
R2 ApHidMonitorService; C:\Program Files\Apoint2K\HidMonitorSvc.exe [117280 2017-02-08] (ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [382424 2018-01-04] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S3 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe [954648 2015-05-07] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-04-23] (ASUSTeK Computer Inc. -> ) [File not signed]
S3 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.00.33\AsusFanControlService.exe [1340376 2017-12-04] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 bzserv; C:\Program Files (x86)\Backblaze\bzserv.exe [543584 2019-02-07] (Backblaze, Inc -> )
S3 ChamClock Set Time Service for Vista; C:\Program Files (x86)\Chameleon Clock\settime.exe [58880 2007-06-27] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9677472 2018-12-30] (Microsoft Corporation -> Microsoft Corporation)
R2 DragonLoggerService; C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe [166288 2018-01-27] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [23288 2018-07-30] (Intel(R) Driver & Support Assistant -> Intel)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2302160 2019-01-03] (ESET, spol. s r.o. -> ESET)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
S3 Everything; C:\Program Files\Everything\Everything.exe [2199656 2018-02-08] (David Carpenter -> )
S4 GladFileMonSvc; C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe [29552 2011-07-26] (Gladinet, Inc. -> Gladinet, INC)
R2 IAStorDataMgrSvc; c:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2017-06-20] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S4 ICEsoundService; C:\WINDOWS\system32\ICEsoundService64.exe [807808 2019-01-31] (ICEpower a/s -> ICEpower)
S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
S4 mmsminisrv; c:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4795288 2017-02-13] (Acronis International GmbH -> Acronis International GmbH)
S3 mobile_backup_server; c:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [2908352 2017-01-06] (Acronis International GmbH -> Acronis International GmbH)
S3 mobile_backup_status_server; c:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [1617520 2017-06-22] (Acronis International GmbH -> )
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [233456 2017-07-03] (Netgear Incorporated -> NETGEAR)
R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [184784 2018-12-04] (TEFINCOM S.A. -> )
S3 Oasis2Service (Intel(R) Device Advisor); C:\Program Files (x86)\DDNi\Oasis2Service (Intel Device Advisor)\Oasis2Service.exe [72472 2016-07-30] (Digital Delivery Networks, Inc. -> Digital Delivery Networks, Inc.)
R2 PowerPanel Personal Service; C:\Program Files (x86)\CyberPower PowerPanel Personal\ppped.exe [11264 2018-07-17] () [File not signed]
S4 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2014-12-10] (Intuit) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2013-10-10] (Intuit Inc.) [File not signed]
S4 QBVSS; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [1248256 2013-08-19] (Intuit Inc.) [File not signed]
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5381128 2019-01-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [745664 2016-01-11] (@ByELDI -> @ByELDI) [File not signed]
R2 SNMP; C:\WINDOWS\System32\snmp.exe [53248 2018-10-12] (Microsoft Windows -> Microsoft Corporation)
R2 SNMP; C:\WINDOWS\SysWOW64\snmp.exe [46592 2018-10-12] (Microsoft Windows -> Microsoft Corporation)
S3 SSDkeeper; C:\Program Files\Condusiv Technologies\SSDkeeper\SkService.exe [3112648 2016-12-23] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
S3 sshd; C:\WINDOWS\System32\OpenSSH\sshd.exe [974848 2019-01-04] (Microsoft Windows -> )
S3 SshdBroker; C:\WINDOWS\System32\SshdBroker.dll [289280 2018-10-12] (Microsoft Windows -> Microsoft Corporation)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-20] (DEVGURU CO LTD -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11665136 2019-01-16] (TeamViewer GmbH -> TeamViewer GmbH)
S3 vmware-converter-agent; C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe [503512 2016-02-09] (VMware, Inc. -> VMware, Inc.)
S3 vmware-converter-server; C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [503512 2016-02-09] (VMware, Inc. -> VMware, Inc.)
S3 vmware-converter-worker; C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [503512 2016-02-09] (VMware, Inc. -> VMware, Inc.)
R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [15446960 2018-11-21] (VMware, Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3830488 2018-09-14] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [110944 2018-09-14] (Microsoft Corporation -> Microsoft Corporation)
S3 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [19192 2015-09-21] (Intel(R) Software -> Intel(R) Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 AlpsHidSmb; C:\WINDOWS\system32\DRIVERS\ApSmbDrv.sys [113728 2017-02-08] (ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.)
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [98848 2017-11-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 ampa; C:\WINDOWS\system32\ampa.sys [38320 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 ampa; C:\WINDOWS\SysWOW64\ampa.sys [38320 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
R3 AmUStor; C:\WINDOWS\system32\drivers\AmUStor.SYS [109504 2019-01-31] (Alcorlink Corp. -> )
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-08] (ASUSTeK Computer Inc. -> )
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2014-02-24] (ASUSTeK Computer Inc. -> )
S3 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv.sys [303712 2018-11-01] (Bluestack Systems, Inc. -> Bluestack System Inc. )
S3 bmdrvr; C:\Windows\SysWow64\drivers\bmdrvr.sys [75992 2016-02-09] (VMware, Inc. -> VMware, Inc.)
S3 BtHidBus; C:\WINDOWS\System32\Drivers\BtHidBus.sys [25056 2011-12-21] (IVT CORPORATION -> IVT Corporation.)
S3 btnetBUs; C:\WINDOWS\System32\Drivers\btnetBus.sys [31968 2011-12-21] (IVT CORPORATION -> IVT Corporation.)
S3 csravrcp; C:\WINDOWS\System32\drivers\csravrcp.sys [26304 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 CsrBthAudioHF; C:\WINDOWS\system32\DRIVERS\CsrBthAudioHF.sys [39120 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 CsrBtPort; C:\WINDOWS\system32\DRIVERS\CsrBtPort.sys [2784968 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrhfgcc; C:\WINDOWS\System32\drivers\csrhfgcc.sys [38080 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrpan; C:\WINDOWS\System32\drivers\csrpan.sys [39616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrserial; C:\WINDOWS\system32\DRIVERS\csrserial.sys [61128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusb; C:\WINDOWS\System32\Drivers\csrusb.sys [47296 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusbfilter; C:\WINDOWS\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csr_bthav; C:\WINDOWS\system32\drivers\csrbthav.sys [99520 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 ddmdrv; C:\WINDOWS\system32\ddmdrv.sys [35760 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 ddmdrv; C:\WINDOWS\SysWOW64\ddmdrv.sys [33200 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 DFX11_1; C:\WINDOWS\system32\drivers\dfx11_1x64.sys [28008 2017-06-19] (Power Technology -> Windows (R) Win 7 DDK provider)
S3 DFX12; C:\WINDOWS\system32\drivers\dfx12x64.sys [39048 2017-06-19] (Power Technology -> Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2018-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 DKDFM; C:\WINDOWS\System32\drivers\DKDFM.sys [41744 2013-05-06] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
S3 DKRtWrt; C:\Windows\system32\drivers\DKRtWrt.sys [48792 2016-01-28] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
R0 DKTLFSMF; C:\WINDOWS\System32\drivers\DKTLFSMF.sys [119536 2014-04-14] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
S3 DrvAgent64; C:\WINDOWS\SysWOW64\Drivers\DrvAgent64.SYS [22200 2018-05-24] (eSupport.com, Inc. -> Phoenix Technologies)
R1 DuoVMDrv; C:\WINDOWS\system32\DRIVERS\DuoVMDrv.sys [246720 2016-05-10] (American Megatrends Inc. -> American Megatrends Inc.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [143448 2018-11-08] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [107896 2018-11-08] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15872 2018-02-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [188832 2018-11-08] (ESET, spol. s r.o. -> ESET)
S4 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [50144 2018-11-08] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [82304 2018-11-08] (ESET, spol. s r.o. -> ESET)
S1 EpfwLWF; C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys [44632 2014-08-18] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [109864 2018-11-08] (ESET, spol. s r.o. -> ESET)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [34496 2018-10-18] (CHENGDU YIWO Tech Development Co., Ltd. -> )
R0 EPMVolFlt; C:\WINDOWS\System32\drivers\EPMVolFlt.sys [30416 2018-10-18] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Codename Longhorn DDK provider)
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [181160 2018-08-08] (ESET, spol. s r.o. -> ESET)
S3 ETDSMBus; C:\WINDOWS\System32\drivers\ETDSMBus.sys [31816 2018-10-08] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronic Corp.)
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2018-10-24] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
S3 EverestDriver; M:\__NEW SYSTEM\Everest Ultimate_5.5\EVEREST Ultimate Edition 5.50.2194 Beta ML_Portable\kerneld.amd64 [26752 2010-06-17] (LAVALYS -> )
R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [378712 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
S3 FlashBoot; C:\WINDOWS\System32\drivers\FlashBoot.sys [17616 2014-04-03] (Challenger Backup Solutions, LLC -> Challenger Backup Solutions, LLC)
R0 hswultpep; C:\WINDOWS\System32\drivers\hswultpep.sys [62968 2013-02-08] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-10-07] (Martin Malik - REALiX -> REALiX(tm))
R0 iaStorAC; C:\WINDOWS\System32\drivers\iaStorAC.sys [967696 2018-10-08] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [30224 2015-09-21] (Intel(R) Software -> Intel Corporation)
S3 IvtBtBUs; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [27016 2010-04-06] (IVT SOFTWARE TECHNOLOGY Inc. -> IVT Corporation.)
S3 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5db32447b43ce666\nvlddmkm.sys [20461984 2019-01-11] (NVIDIA Corporation -> NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [70024 2018-10-01] (NVIDIA Corporation -> NVIDIA Corporation)
U5 PROCMON24; C:\Windows\System32\Drivers\PROCMON24.sys [93960 2019-02-06] (Microsoft Windows Hardware Compatibility Publisher -> Sysinternals - www.sysinternals.com)
S3 ptun0901; C:\WINDOWS\System32\drivers\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project) [File not signed]
R0 PxHlpa64; C:\WINDOWS\System32\drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation -> Corel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1139848 2019-01-31] (Realtek Semiconductor Corp. -> Realtek )
S3 RTCore64; C:\Program Files (x86)\RMClock\RTCore64.sys [7168 2005-05-25] () [File not signed]
R0 secnvme; C:\WINDOWS\System32\drivers\secnvme.sys [134120 2018-02-13] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd)
R2 Sentinel64; C:\WINDOWS\System32\Drivers\Sentinel64.sys [145448 2008-07-11] (SafeNet, Inc. -> SafeNet, Inc.)
R3 Serial; C:\WINDOWS\system32\DRIVERS\wdfserial.sys [80664 2015-03-06] (LG Electronics Inc. -> LG Electronics Inc.)
R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit Information Technology -> IObit)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (The OpenVPN Project) [File not signed]
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [84432 2017-03-26] (TEFINCOM S.A. -> The OpenVPN Project)
S3 tbhsd; C:\WINDOWS\system32\drivers\tbhsd.sys [57648 2019-01-11] (Audials AG -> RapidSolution Software AG)
R1 tcefs; C:\Windows\system32\drivers\tcefs.sys [26776 2015-08-18] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies Corporation)
R0 tcesd; C:\WINDOWS\System32\drivers\tcesd.sys [238320 2016-07-19] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies Corporation)
R0 tib; C:\WINDOWS\System32\DRIVERS\tib.sys [1310552 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [213336 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
S3 tnd; C:\WINDOWS\system32\DRIVERS\tnd.sys [690520 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R3 TotRec8; C:\WINDOWS\system32\drivers\TotRec8.sys [126080 2015-10-20] (High Criteria Inc -> High Criteria inc.)
R1 UimBus; C:\WINDOWS\System32\drivers\uimbus.sys [108896 2017-09-12] (Paragon Software GmbH -> Paragon Software GmbH)
R1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [25904 2015-11-10] (Paragon Software GmbH -> )
R1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [701360 2015-11-10] (Paragon Software GmbH -> )
R3 USBPcap; C:\WINDOWS\system32\DRIVERS\USBPcap.sys [50224 2017-08-20] (Tomasz Moń -> USBPcap)
R1 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-01-16] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [205440 2017-01-16] (Oracle Corporation -> Oracle Corporation)
R2 virtual_file; C:\WINDOWS\System32\DRIVERS\virtual_file.sys [324952 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R1 vmkbd3; C:\WINDOWS\system32\DRIVERS\vmkbd.sys [52288 2016-11-11] (VMware, Inc. -> VMware, Inc.)
R0 vsock; C:\WINDOWS\System32\DRIVERS\vsock.sys [92040 2018-06-22] (VMware, Inc. -> VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [35032 2016-02-09] (VMware, Inc. -> VMware, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46584 2018-09-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [340008 2018-09-14] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [61992 2018-09-14] (Microsoft Windows -> Microsoft Corporation)
R2 WinRing0_1_2_0; C:\Program Files (x86)\EVGA\Precision XOC\WinRing0\WinRing0x64.sys [14536 2015-10-20] (EVGA -> OpenLibSys.org)
S3 AscFileFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys [X]
S3 AscRegistryFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys [X]
S3 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X]
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win10_x64.sys [X]
S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-02-13 12:41 - 2019-02-13 12:42 - 000081067 _ C:\Users\Robert\Desktop\FRST.txt
2019-02-13 12:35 - 2019-02-13 12:35 - 002433536 _ (Farbar) C:\Users\Robert\Desktop\FRST64.exe
2019-02-13 02:59 - 2019-02-13 11:59 - 000000130 C:\Users\Robert\AppData\Roaming\Network Monitor II#0_Traffic.ini
2019-02-13 00:48 - 2019-02-13 00:48 - 000000383 _ C:\Users\Robert\AppData\Roaming\Top Process Monitor_Settings.ini
2019-02-13 00:44 - 2019-02-13 00:44 - 000000266 _ C:\Users\Robert\AppData\Roaming\World Population Monitor_Settings.ini
2019-02-13 00:12 - 2019-02-13 00:15 - 000000521 _ C:\Users\Robert\AppData\Roaming\Weather Monitor_Settings.ini
2019-02-13 00:00 - 2019-02-13 00:41 - 000000604 _ C:\Users\Robert\AppData\Roaming\Drives Monitor_Settings.ini
2019-02-12 23:49 - 2019-02-12 23:49 - 000000985 C:\Users\Robert\AppData\Roaming\Network Monitor II#0_Settings.ini
2019-02-12 22:45 - 2019-02-12 22:45 - 000003074 _ C:\Users\Robert\AppData\Roaming\SAS7_000.DAT
2019-02-12 05:04 - 2019-02-12 05:04 - 000004562 _ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-02-11 18:26 - 2019-02-11 18:26 - 000016612 _ C:\Users\Robert\Desktop\ListChkdskResult.txt
2019-02-11 18:24 - 2019-02-11 18:24 - 000016612 _ C:\Users\Robert\Desktop\ListChkdskResult1.txt
2019-02-11 17:27 - 2019-02-11 17:28 - 000197679 _ C:\Users\Robert\Desktop\ListChkdskResult.exe
2019-02-11 09:29 - 2019-02-11 09:35 - 011942934 _ C:\WINDOWS\system32\Drivers\etc\HOSTS.bak
2019-02-11 09:12 - 2019-02-11 09:12 - 000003825 _ C:\WINDOWS\system32\Drivers\etc\hosts.txt
2019-02-11 08:45 - 2019-02-11 08:45 - 000001687 _ C:\Users\Robert\Desktop\Hosts File Editor+ v.1.5.7.exe.lnk
2019-02-11 07:54 - 2019-02-11 07:57 - 000008628 ____H C:\Users\Robert\Desktop\DELAYER.GID
2019-02-11 07:54 - 2019-02-11 07:54 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Help
2019-02-11 07:52 - 2008-04-14 03:00 - 000283648 _ (Microsoft Corporation) C:\Users\Robert\Desktop\winhlp32.exe
2019-02-11 00:02 - 2001-09-27 16:43 - 000049152 _ (Cottonwood Software) C:\Delayer.exe
2019-02-11 00:02 - 1997-04-03 20:55 - 000016908 _ C:\Users\Robert\Desktop\DELAYER.HLP
2019-02-11 00:01 - 2019-02-11 00:01 - 000000000 ____D C:\Program Files (x86)\delayer11
2019-02-10 16:17 - 2019-02-10 16:17 - 000000840 __RSH C:\ProgramData\ntuser.pol
2019-02-08 17:12 - 2019-02-08 17:12 - 000001444 _ C:\Users\Public\Desktop\Spybot Anti-Beacon.lnk
2019-02-08 17:12 - 2019-02-08 17:12 - 000000000 ____D C:\WINDOWS\SysWOW64\PolicyDefinitions
2019-02-08 17:12 - 2019-02-08 17:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot Anti-Beacon
2019-02-08 16:37 - 2019-02-08 17:12 - 000000000 ____D C:\Program Files (x86)\Safer-Networking Ltd
2019-02-08 16:37 - 2019-02-08 16:37 - 000000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2019-02-08 09:29 - 2019-02-10 22:32 - 000000117 _ C:\Users\Robert\AppData\Roaming\System Monitor II_UptimeRecord.ini
2019-02-08 06:28 - 2019-02-08 22:32 - 000003978 _ C:\Users\Robert\AppData\Roaming\System Monitor II_CPU0_Settings.ini
2019-02-07 10:14 - 2019-02-07 10:14 - 000001227 _ C:\Users\Public\Desktop\AOMEI Partition Assistant Professional Edition 8.0.lnk
2019-02-07 10:14 - 2019-02-07 10:14 - 000001024 ____H C:\AMTAG.BIN
2019-02-07 10:13 - 2019-02-08 16:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Partition Assistant
2019-02-07 10:13 - 2019-02-07 10:17 - 000000000 ____D C:\Program Files (x86)\AOMEI Partition Assistant
2019-02-07 10:13 - 2019-01-25 20:48 - 002165096 _ C:\WINDOWS\ampa.exe
2019-02-07 10:13 - 2016-12-27 18:45 - 000035760 _ C:\WINDOWS\system32\ddmdrv.sys
2019-02-07 10:13 - 2016-12-27 18:45 - 000033200 _ C:\WINDOWS\SysWOW64\ddmdrv.sys
2019-02-07 10:13 - 2016-12-27 14:15 - 000038320 _ C:\WINDOWS\SysWOW64\ampa.sys
2019-02-07 10:13 - 2016-12-27 14:15 - 000038320 _ C:\WINDOWS\system32\ampa.sys
2019-02-07 10:13 - 2016-09-29 09:44 - 001298584 _ C:\WINDOWS\ddmmain.exe
2019-02-06 17:37 - 2019-02-06 17:38 - 000000128 _ C:\Users\Robert\AppData\Roaming\Earthquakes Meter_Settings.ini
2019-02-06 17:24 - 2019-02-12 22:44 - 000000593 _ C:\Users\Robert\IP_Log_Data.js
2019-02-06 17:19 - 2019-02-07 20:33 - 000000634 _ C:\Users\Robert\AppData\Roaming\All CPU MeterV3_Settings.ini
2019-02-06 17:12 - 2019-02-06 17:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\8GadgetPack
2019-02-06 17:09 - 2019-02-06 17:09 - 000003254 _ C:\WINDOWS\System32\Tasks\SidebarExecute
2019-02-06 17:08 - 2019-02-08 16:51 - 000000000 ____D C:\Program Files\Rainmeter
2019-02-06 15:32 - 2019-02-06 15:32 - 000093960 ____H (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCMON24.SYS
2019-02-06 14:24 - 2019-02-06 14:24 - 000003392 _ C:\WINDOWS\System32\Tasks\EVGAPrecisionX
2019-02-06 13:39 - 2019-02-06 13:39 - 000000000 ____D C:\Tempzxpsign81d248e10da06351
2019-02-06 13:39 - 2019-02-06 13:39 - 000000000 ____D C:\Tempzxpsign1fd4227f11420fcf
2019-02-05 12:43 - 2019-02-05 12:43 - 000002471 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2019-02-05 12:43 - 2019-02-05 12:43 - 000002118 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2019-02-05 12:23 - 2019-02-05 12:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 64-bit fixes
2019-02-04 12:34 - 2019-02-04 12:34 - 000000139 _ C:\Users\Robert\Desktop\SFCFix.zip
2019-02-04 12:33 - 2019-02-04 12:33 - 002347008 _ (niemiro) C:\Users\Robert\Desktop\SFCFix.exe
2019-02-02 12:19 - 2019-02-02 12:19 - 000774560 _ C:\WINDOWS\system32\FNTCACHE.DAT
2019-02-01 10:39 - 2019-02-01 10:59 - 000000000 ____D C:\Program Files (x86)\Audials 2019
2019-02-01 10:39 - 2019-02-01 10:57 - 000000000 ____D C:\ProgramData\RapidSolution
2019-02-01 09:55 - 2019-02-08 09:56 - 000000000 ____D C:\WINDOWS\System32\Tasks\Abelssoft
2019-02-01 09:55 - 2019-02-01 09:55 - 000001980 _ C:\Users\Public\Desktop\SSDFresh.lnk
2019-02-01 09:55 - 2019-02-01 09:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSDFresh
2019-02-01 09:55 - 2019-02-01 09:55 - 000000000 ____D C:\ProgramData\Abelssoft
2019-02-01 09:55 - 2019-02-01 09:55 - 000000000 ____D C:\Program Files (x86)\SSDFresh
2019-01-31 20:17 - 2019-01-31 20:17 - 000001160 _ C:\Users\Robert\Desktop\Hard Disk Sentinel.lnk
2019-01-31 20:17 - 2019-01-31 20:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hard Disk Sentinel
2019-01-31 11:41 - 2019-01-31 11:41 - 072520776 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2019-01-31 11:41 - 2019-01-31 11:41 - 023073815 _ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2019-01-31 11:41 - 2019-01-31 11:41 - 007178544 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 007101824 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 006270264 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 005347072 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003677224 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2019-01-31 11:41 - 2019-01-31 11:41 - 003418072 _ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003319480 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003306896 _ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003281232 _ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003159472 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003128888 _ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 002930216 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 002444760 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 002198048 _ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001971448 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001965232 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001788032 _ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001598472 _ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001544328 _ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOProp.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001516368 _ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001448856 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOv251gm.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001435216 _ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001396232 _ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001382312 _ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001372472 _ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOv251.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001353384 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001337720 _ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001318912 _ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001282616 _ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001259808 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOvlldp.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001180584 _ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001164696 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOvlldpgm.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001159264 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001073736 _ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001027888 _ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000994744 _ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000965088 _ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000888616 _ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000873544 _ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000852208 _ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000807808 _ (ICEpower) C:\WINDOWS\system32\ICEsoundService64.exe
2019-01-31 11:41 - 2019-01-31 11:41 - 000751376 _ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000734848 _ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000715720 _ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000692224 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000604872 _ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000541192 _ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000511720 _ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000467232 _ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000453352 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000452816 _ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000448680 _ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000447256 _ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000416584 _ (Harman) C:\WINDOWS\system32\HMUI.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000406528 _ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2APIPCLL.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000392936 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000381488 _ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000378456 _ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000367688 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000366200 _ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000360424 _ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000343768 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000341224 _ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000341224 _ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000333088 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000327336 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000327328 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000316080 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000278352 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000266616 _ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000261312 _ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000261280 _ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000260288 _ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000231976 _ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000230784 _ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000220448 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000218352 _ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000203912 _ (Harman) C:\WINDOWS\system32\HMHVS.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000195763 _ C:\WINDOWS\system32\ICEsoundService.bin
2019-01-31 11:41 - 2019-01-31 11:41 - 000191008 _ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000191008 _ (Harman) C:\WINDOWS\system32\HMEQ.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000179672 _ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000175824 _ (ASUSTeK COMPUTER INC.) C:\WINDOWS\system32\ATKWMI.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000175016 _ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000158776 _ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000157408 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000154440 _ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000139832 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000122424 _ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000118664 _ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000116600 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000105384 _ C:\WINDOWS\system32\audioLibVc.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000093968 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000090976 _ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000090232 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000088384 _ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000083688 _ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000075616 _ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2019-01-31 11:40 - 2019-01-31 11:40 - 001139848 _ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2019-01-31 11:19 - 2019-01-31 11:19 - 001083424 _ C:\WINDOWS\system32\AmRdrIco.icl
2019-01-31 11:17 - 2019-01-31 11:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Driver Booster PRO
2019-01-31 11:16 - 2019-01-31 11:16 - 000000000 ____D C:\2-click run
2019-01-31 10:45 - 2019-01-31 10:45 - 025117952 _ (StarWind Software ) C:\Users\Robert\Desktop\starwindconverterV9.110.exe
2019-01-30 23:31 - 2019-01-30 23:31 - 363172271 _ C:\Users\Robert\Desktop\An FBI Negotiator’s Secret to Winning Any Exchange _ Inc.mp4
2019-01-30 18:22 - 2019-01-30 18:22 - 008406934 _ C:\Users\Robert\Desktop\COMPONENTS.zip
2019-01-30 18:13 - 2019-02-06 13:15 - 000000000 ____D C:\Users\Robert\AppData\Roaming\epm
2019-01-30 13:22 - 2019-01-30 13:22 - 000001411 _ C:\Users\Public\Desktop\EaseUS Partition Master 13.0.lnk
2019-01-30 13:22 - 2019-01-30 13:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 13.0
2019-01-30 13:22 - 2018-11-27 12:08 - 005247120 _ C:\WINDOWS\system32\BootMan.exe
2019-01-30 13:22 - 2018-11-27 12:08 - 003551376 _ C:\WINDOWS\SysWOW64\BootMan.exe
2019-01-30 13:22 - 2018-11-27 12:08 - 000022160 _ C:\WINDOWS\SysWOW64\EuEpmGdi.dll
2019-01-30 13:22 - 2018-11-27 12:08 - 000018576 _ C:\WINDOWS\system32\EuEpmGdi.dll
2019-01-30 13:22 - 2018-10-24 13:53 - 000010848 _ C:\WINDOWS\system32\EuGdiDrv.sys
2019-01-30 13:22 - 2018-10-18 13:05 - 000132240 _ C:\WINDOWS\system32\setupempdrvx64.exe
2019-01-30 13:22 - 2018-10-18 04:35 - 000034496 _ C:\WINDOWS\system32\epmntdrv.sys
2019-01-30 13:22 - 2018-10-18 01:38 - 000030416 _ (Windows (R) Codename Longhorn DDK provider) C:\WINDOWS\system32\EPMVolFlt.sys
2019-01-30 13:22 - 2018-10-18 01:38 - 000030416 _ (Windows (R) Codename Longhorn DDK provider) C:\WINDOWS\system32\Drivers\EPMVolFlt.sys
2019-01-29 22:05 - 2019-01-29 22:49 - 000000894 _ C:\Users\Robert\Desktop\Chris Star Trek reference notes.txt
2019-01-29 12:15 - 2019-01-29 12:15 - 000000979 _ C:\Users\Robert\Desktop\Sweet Home 3D.lnk
2019-01-29 12:15 - 2019-01-29 12:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eTeks Sweet Home 3D
2019-01-26 18:36 - 2019-02-13 12:41 - 000000000 ____D C:\FRST
2019-01-25 13:49 - 2019-01-25 13:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\smartmontools
2019-01-25 13:49 - 2019-01-25 13:49 - 000000000 ____D C:\Program Files\smartmontools
2019-01-25 13:41 - 2019-01-25 13:41 - 001265846 _ (www.smartmontools.org) C:\Users\Robert\Desktop\smartmontools-7.0-1.win32-setup.exe
2019-01-25 13:01 - 2019-02-07 09:39 - 000000000 ____D C:\Users\Robert\AppData\Roaming\gsmartcontrol
2019-01-25 13:00 - 2019-02-07 09:39 - 000000000 ____D C:\Users\Robert\Desktop\gsmartcontrol-1.1.3-win32
2019-01-25 12:59 - 2019-01-25 12:59 - 010745236 _ C:\Users\Robert\Desktop\gsmartcontrol-1.1.3-win32.zip
2019-01-24 19:54 - 2019-01-24 19:54 - 000002465 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002455 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002454 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002418 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002417 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002411 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002405 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002397 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-01-24 19:54 - 2019-01-24 19:54 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2019-01-24 19:51 - 2019-01-24 19:51 - 000000000 ____D C:\Program Files\Microsoft Office 15
2019-01-24 19:18 - 2019-01-24 19:18 - 000003340 _ C:\WINDOWS\System32\Tasks\Office 2019 Statique Activation Planificateur
2019-01-24 18:48 - 2019-01-24 18:48 - 000003356 _ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2536635842-542287166-2959069790-1002
2019-01-24 18:48 - 2019-01-24 18:48 - 000002404 _ C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-01-24 18:21 - 2019-01-24 19:54 - 000000000 ____D C:\Program Files\Microsoft Office
2019-01-18 11:33 - 2019-01-18 11:34 - 000141924 ____R C:\Users\Robert\Desktop\Markup and Margin Sheet.pdf
2019-01-18 01:22 - 2019-02-04 12:35 - 000000000 ____D C:\SFCFix
2019-01-17 15:17 - 2019-02-09 22:32 - 000000000 ____D C:\Users\Robert\Desktop\Hiren's BootCD WinPE10 Premium Edition Build 181211 (Dec. 11, 2018) [CracksNow]
2019-01-17 09:45 - 2019-01-17 09:45 - 000002142 _ C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2019-01-17 09:45 - 2019-01-17 09:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2019-01-17 01:34 - 2019-01-17 01:34 - 000000887 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr. Folder.lnk
2019-01-16 18:07 - 2019-01-16 18:07 - 000002095 _ C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
2019-01-16 17:11 - 2019-02-12 22:43 - 141557760 _ C:\WINDOWS\system32\config\SOFTWARE
2019-01-16 17:11 - 2019-02-12 22:43 - 026738688 _ C:\WINDOWS\system32\config\SYSTEM
2019-01-16 17:11 - 2019-02-12 22:43 - 001048576 _ C:\WINDOWS\system32\config\DEFAULT
2019-01-16 17:11 - 2019-02-12 22:43 - 000077824 _ C:\WINDOWS\system32\config\SAM
2019-01-16 17:11 - 2019-02-12 22:43 - 000073728 _ C:\WINDOWS\system32\config\SECURITY
2019-01-15 13:52 - 2019-01-15 13:52 - 000002055 _ C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\NordVPN.lnk
2019-01-15 13:40 - 2019-01-15 13:40 - 000000958 _ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2019-01-15 13:40 - 2019-01-15 13:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2019-01-15 13:40 - 2016-12-21 14:52 - 000040240 _ (VS Revo Group) C:\WINDOWS\system32\Drivers\revoflt.sys
2019-01-15 12:51 - 2019-01-11 01:31 - 000133328 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2019-01-15 12:51 - 2019-01-11 01:22 - 000125320 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000978336 _ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000978336 _ C:\WINDOWS\system32\vulkan-1.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000845216 _ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000845216 _ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000552536 _ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000456848 _ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000268192 _ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2019-01-15 12:49 - 2019-01-11 20:05 - 000268192 _ C:\WINDOWS\system32\vulkaninfo.exe
2019-01-15 12:49 - 2019-01-11 20:05 - 000243616 _ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2019-01-15 12:49 - 2019-01-11 20:05 - 000243616 _ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-01-15 12:49 - 2019-01-11 20:04 - 004946232 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 004316304 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 002018392 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6441771.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 002003600 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 001512352 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 001467864 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6441771.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 001461152 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 001126544 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 000750520 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 000631896 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 000609368 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 000521688 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-01-15 12:49 - 2019-01-11 20:03 - 040262912 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-01-15 12:49 - 2019-01-11 20:03 - 035158736 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-01-15 12:49 - 2019-01-11 16:03 - 015911384 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 013205768 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001471424 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001462024 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001167584 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001151984 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001145536 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 000914400 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 000822392 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 000794448 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 000637664 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-01-15 12:49 - 2019-01-11 16:01 - 019717352 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-01-15 12:49 - 2019-01-11 16:01 - 016993240 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-01-15 12:49 - 2019-01-11 16:01 - 005003032 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2019-01-15 12:49 - 2019-01-11 16:01 - 004260704 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2019-01-15 12:49 - 2019-01-11 03:06 - 000048472 _ C:\WINDOWS\system32\nvinfo.pb
2019-01-15 11:14 - 2019-02-12 22:43 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2019-01-15 11:14 - 2019-01-22 09:03 - 000001046 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 14.lnk
2019-01-15 11:14 - 2019-01-22 09:03 - 000001034 _ C:\Users\Public\Desktop\TeamViewer 14.lnk
2019-01-15 10:38 - 2019-01-15 10:38 - 000000037 _ C:\Users\Robert\Desktop\SBDC Webinar.txt
2019-01-15 09:58 - 2019-01-15 13:32 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Zoom
2019-01-14 14:23 - 2019-01-14 14:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon
2019-01-14 14:16 - 2019-01-14 14:16 - 000001919 _ C:\ProgramData\Microsoft\Windows\Start Menu\Software Updates.lnk
2019-01-14 10:56 - 2019-01-14 10:56 - 000000043 _ C:\WINDOWS\gswin32.ini
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-02-13 12:42 - 2019-01-03 02:13 - 000000000 ____D C:\Temp
2019-02-13 12:28 - 2018-10-04 03:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-02-13 09:23 - 2018-11-03 07:15 - 000000000 ____D C:\Program Files\Waterfox
2019-02-13 03:00 - 2018-10-04 02:39 - 000000000 ____D C:\WINDOWS\system32\msmq
2019-02-13 00:43 - 2017-01-11 22:55 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Everything
2019-02-13 00:35 - 2017-12-28 08:02 - 000000339 _ C:\Users\Robert\AppData\Roaming\Drives Meter_Settings.ini
2019-02-12 23:49 - 2017-12-28 15:56 - 000000025 _ C:\Users\Robert\AppData\Roaming\Network Meter_Usage.ini
2019-02-12 23:00 - 2017-12-28 11:00 - 000010427 _ C:\Users\Robert\Network_Meter_Data.js
2019-02-12 22:49 - 2018-10-04 03:44 - 000946072 _ C:\WINDOWS\system32\PerfStringBackup.INI
2019-02-12 22:49 - 2018-09-14 23:31 - 000000000 ____D C:\WINDOWS\INF
2019-02-12 22:44 - 2018-10-07 22:39 - 000000000 ____D C:\ProgramData\ProductData
2019-02-12 22:44 - 2018-09-14 23:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-02-12 22:44 - 2017-08-03 15:50 - 000000000 ____D C:\Program Files (x86)\Chameleon Clock
2019-02-12 22:43 - 2018-10-04 03:40 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-02-12 22:43 - 2018-10-02 12:14 - 000000000 ____D C:\ProgramData\NVIDIA
2019-02-12 22:43 - 2018-09-14 22:09 - 000524288 _ C:\WINDOWS\system32\config\BBI
2019-02-12 22:43 - 2017-01-12 08:00 - 000000000 ____D C:\ProgramData\VMware
2019-02-12 20:49 - 2017-01-19 15:33 - 000000000 ____D C:\Users\Robert\AppData\Roaming\qBittorrent
2019-02-12 18:05 - 2019-01-03 11:02 - 000004146 _ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{8E893A56-B045-48A2-8817-29DB664228F5}
2019-02-11 17:07 - 2017-01-12 22:15 - 000000000 ____D C:\ProgramData\Temp
2019-02-11 12:54 - 2016-07-16 03:47 - 000000180 _ C:\WINDOWS\win.ini
2019-02-11 09:47 - 2017-01-20 08:36 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-02-11 09:25 - 2018-04-17 18:53 - 000000000 ____D C:\Program Files (x86)\Host File Editor
2019-02-11 08:01 - 2017-01-12 19:38 - 000000000 ____D C:\Users\Robert\AppData\Roaming\VMware
2019-02-11 07:54 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-02-10 23:26 - 2018-10-04 02:41 - 000000000 ____D C:\Users\Robert
2019-02-10 19:39 - 2018-09-08 12:39 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Photolemur
2019-02-10 17:59 - 2018-11-18 22:52 - 000000000 ____D C:\Users\Robert\AppData\Roaming\MPC-HC
2019-02-10 14:53 - 2017-01-19 12:16 - 000000000 ____D C:\Users\Robert\AppData\Roaming\XnView
2019-02-10 11:53 - 2018-11-16 06:51 - 000526346 _ C:\WINDOWS\system32\Drivers\etc\hosts.020919
2019-02-10 11:22 - 2018-11-17 21:14 - 000001474 _ C:\Users\Robert\Desktop\WaterFox settings mod.txt
2019-02-09 16:02 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-02-09 14:35 - 2018-06-16 09:14 - 000000000 ____D C:\ProgramData\ThumbsPlus
2019-02-09 14:35 - 2017-01-13 10:42 - 000000000 ____D C:\Users\Robert\AppData\Roaming\ThumbsPlus
2019-02-08 16:46 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-02-07 16:55 - 2017-01-12 22:52 - 000000000 ____D C:\Program Files (x86)\Backblaze
2019-02-07 16:21 - 2018-02-14 08:02 - 000002305 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-02-07 10:02 - 2017-12-28 20:44 - 000001050 _ C:\Users\Robert\AppData\Roaming\Network Meter_Settings.ini
2019-02-07 02:17 - 2018-09-22 00:27 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant
2019-02-06 21:14 - 2018-10-26 17:43 - 000000000 ____D C:\Users\Robert\Desktop\comp
2019-02-06 17:13 - 2018-09-14 23:33 - 000000000 ___SD C:\Program Files\Windows Sidebar
2019-02-06 17:13 - 2018-09-14 23:33 - 000000000 ___SD C:\Program Files (x86)\Windows Sidebar
2019-02-06 13:56 - 2017-01-11 17:42 - 000000000 ____D C:\Users\Robert\AppData\LocalLow\Mozilla
2019-02-06 13:53 - 2018-10-19 19:56 - 000017878 _ C:\Users\Robert\Desktop\Markup calculator.xlsx
2019-02-06 13:53 - 2018-07-03 10:03 - 000000000 ____D C:\Users\Robert\AppData\Roaming\XnViewMP
2019-02-06 12:48 - 2019-01-03 13:24 - 000002532 _ C:\WINDOWS\System32\Tasks\SamsungMagician
2019-02-06 12:36 - 2018-07-01 14:10 - 000002548 ____H C:\WINDOWS\EPMBatch.ept
2019-02-05 22:32 - 2017-01-18 22:44 - 000000000 ____D C:\Users\Robert\AppData\Roaming\ObviousIdea
2019-02-05 12:25 - 2017-01-19 09:45 - 000000000 ____D C:\Program Files\CCleaner
2019-02-05 12:25 - 2017-01-14 08:22 - 000000000 ____D C:\Program Files (x86)\Adobe Reader 64-bit fixes
2019-02-05 12:25 - 2017-01-11 17:38 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-02-05 11:06 - 2018-06-03 10:57 - 000000673 _ C:\WINDOWS\clipc.INI
2019-02-04 21:48 - 2017-01-11 21:28 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2019-02-02 12:02 - 2018-10-06 19:48 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\- SYSTEM Test
2019-02-01 11:19 - 2017-01-19 15:48 - 000000000 ____D C:\Program Files\Adobe
2019-01-31 20:17 - 2017-01-17 00:15 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2019-01-31 11:43 - 2018-10-07 22:33 - 000000000 ____D C:\Users\Robert\AppData\LocalLow\IObit
2019-01-31 11:43 - 2018-10-07 22:32 - 000000000 ____D C:\ProgramData\IObit
2019-01-31 11:43 - 2018-10-02 17:32 - 000000000 ____D C:\Users\Robert\AppData\Roaming\IObit
2019-01-31 11:41 - 2018-10-30 22:27 - 006400040 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2019-01-31 11:41 - 2018-10-30 22:27 - 003761640 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2019-01-31 11:41 - 2018-10-30 22:27 - 000193040 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2019-01-31 11:41 - 2018-10-30 22:27 - 000023752 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2019-01-31 11:41 - 2018-07-21 23:42 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2019-01-31 11:41 - 2018-07-21 23:38 - 000000000 ____D C:\WINDOWS\system32\RTCOM
2019-01-31 11:41 - 2017-04-12 06:16 - 000000000 ____D C:\WINDOWS\system32\DAX2
2019-01-31 11:19 - 2018-01-22 11:45 - 000109504 _ () C:\WINDOWS\system32\Drivers\AmUStor.sys
2019-01-30 18:35 - 2018-08-28 09:05 - 000000000 ____D C:\Users\Robert\AppData\Roaming\ON1
2019-01-30 13:22 - 2018-07-01 14:04 - 000000000 ____D C:\Program Files (x86)\EaseUS Partition Master
2019-01-30 13:22 - 2017-01-28 10:46 - 000000000 ____D C:\Program Files (x86)\EaseUS
2019-01-29 12:15 - 2017-01-11 22:38 - 000000000 ____D C:\Program Files\Sweet Home 3D
2019-01-28 21:17 - 2018-09-14 23:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-01-25 00:32 - 2019-01-04 22:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2019-01-25 00:32 - 2018-10-02 12:13 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-01-25 00:32 - 2018-10-02 12:13 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-01-25 00:32 - 2018-10-02 12:13 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-01-24 19:54 - 2018-09-14 23:33 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-01-24 18:48 - 2018-07-23 23:10 - 000000000 ___RD C:\Users\Robert\OneDrive
2019-01-24 18:07 - 2018-07-23 23:23 - 000000000 ____D C:\Program Files\Office
2019-01-24 13:37 - 2017-08-24 16:55 - 000042904 _ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2019-01-21 00:49 - 2019-01-13 16:45 - 000004210 _ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-01-17 14:05 - 2018-12-01 11:08 - 000000000 ____D C:\Program Files (x86)\SpeedFan
2019-01-17 13:40 - 2018-11-03 09:29 - 000000000 ____D C:\Windows10Upgrade
2019-01-17 09:45 - 2018-08-18 03:21 - 000000000 ____D C:\Users\Robert\AppData\Roaming\MyPhoneExplorer
2019-01-17 09:45 - 2018-08-18 03:21 - 000000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2019-01-17 01:34 - 2017-01-19 12:29 - 000000000 ____D C:\Program Files\Dr. Folder
2019-01-16 19:43 - 2018-09-14 23:33 - 000000000 ___HD C:\Program Files\WindowsApps.tmp
2019-01-16 19:02 - 2018-09-14 23:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-01-16 19:02 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\registration
2019-01-16 17:42 - 2017-07-08 13:20 - 000000000 ____D C:\Program Files (x86)\XnView
2019-01-16 17:12 - 2018-11-12 22:05 - 132120576 _ C:\WINDOWS\system32\config\software.rcbak
2019-01-16 17:12 - 2018-11-12 22:05 - 026214400 _ C:\WINDOWS\system32\config\system.rcbak
2019-01-16 17:12 - 2018-11-12 22:05 - 000786432 _ C:\WINDOWS\system32\config\default.rcbak
2019-01-16 17:12 - 2018-11-12 22:05 - 000155648 _ C:\WINDOWS\system32\config\sam.rcbak
2019-01-16 17:12 - 2018-11-12 22:05 - 000065536 _ C:\WINDOWS\system32\config\security.rcbak
2019-01-16 14:40 - 2018-02-04 18:56 - 000000000 ____D C:\Program Files (x86)\TinyTask
2019-01-16 14:01 - 2018-09-22 10:49 - 000000000 ____D C:\Program Files (x86)\FotoSketcher
2019-01-15 17:36 - 2018-09-14 22:09 - 006533120 _ C:\WINDOWS\system32\config\drivers.rcbak
2019-01-15 13:55 - 2017-02-05 01:32 - 000000000 ____D C:\Program Files\Revo Uninstaller Pro
2019-01-15 13:52 - 2019-01-12 17:38 - 000001986 _ C:\Users\Public\Desktop\NordVPN.lnk
2019-01-15 01:04 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-01-14 22:21 - 2018-08-09 00:16 - 000000000 ____D C:\ProgramData\Packages
2019-01-14 11:17 - 2018-04-11 15:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
==================== Files in the root of some directories =======
2003-08-07 08:34 - 2003-08-07 08:34 - 000000000 _ () C:\ProgramData\sdpsenv.dat
2016-02-04 10:11 - 2016-02-04 10:11 - 000002045 _ () C:\ProgramData\whlb32g.dll
2019-02-06 17:24 - 2019-02-12 22:44 - 000000593 _ () C:\Users\Robert\IP_Log_Data.js
2017-12-28 11:00 - 2019-02-12 23:00 - 000010427 _ () C:\Users\Robert\Network_Meter_Data.js
2017-01-31 11:57 - 2003-10-30 11:00 - 000353280 _ (Stardust Software) C:\Program Files (x86)\SCMain.exe
2019-02-06 17:19 - 2019-02-07 20:33 - 000000634 _ () C:\Users\Robert\AppData\Roaming\All CPU MeterV3_Settings.ini
2017-12-28 10:10 - 2018-01-07 01:48 - 000000412 _ () C:\Users\Robert\AppData\Roaming\All CPU Meter_Settings.ini
2017-12-28 08:02 - 2019-02-13 00:35 - 000000339 _ () C:\Users\Robert\AppData\Roaming\Drives Meter_Settings.ini
2019-02-13 00:00 - 2019-02-13 00:41 - 000000604 _ () C:\Users\Robert\AppData\Roaming\Drives Monitor_Settings.ini
2019-02-06 17:37 - 2019-02-06 17:38 - 000000128 _ () C:\Users\Robert\AppData\Roaming\Earthquakes Meter_Settings.ini
2018-10-18 09:51 - 2018-10-18 09:51 - 000000312 _ () C:\Users\Robert\AppData\Roaming\license
2017-12-28 20:44 - 2019-02-07 10:02 - 000001050 _ () C:\Users\Robert\AppData\Roaming\Network Meter_Settings.ini
2017-12-28 15:56 - 2019-02-12 23:49 - 000000025 _ () C:\Users\Robert\AppData\Roaming\Network Meter_Usage.ini
2019-02-12 23:49 - 2019-02-12 23:49 - 000000985 () C:\Users\Robert\AppData\Roaming\Network Monitor II#0_Settings.ini
2019-02-13 02:59 - 2019-02-13 11:59 - 000000130 () C:\Users\Robert\AppData\Roaming\Network Monitor II#0_Traffic.ini
2018-10-02 12:36 - 2018-10-16 21:56 - 000000270 _ () C:\Users\Robert\AppData\Roaming\pppe_log.txt
2019-02-12 22:45 - 2019-02-12 22:45 - 000003074 _ () C:\Users\Robert\AppData\Roaming\SAS7_000.DAT
2017-11-05 08:53 - 2017-11-08 09:03 - 000601088 _ () C:\Users\Robert\AppData\Roaming\SharedSettings.ccs
2019-02-08 06:28 - 2019-02-08 22:32 - 000003978 _ () C:\Users\Robert\AppData\Roaming\System Monitor II_CPU0_Settings.ini
2019-02-08 09:29 - 2019-02-10 22:32 - 000000117 _ () C:\Users\Robert\AppData\Roaming\System Monitor II_UptimeRecord.ini
2019-02-13 00:48 - 2019-02-13 00:48 - 000000383 _ () C:\Users\Robert\AppData\Roaming\Top Process Monitor_Settings.ini
2019-02-13 00:12 - 2019-02-13 00:15 - 000000521 _ () C:\Users\Robert\AppData\Roaming\Weather Monitor_Settings.ini
2019-02-13 00:44 - 2019-02-13 00:44 - 000000266 _ () C:\Users\Robert\AppData\Roaming\World Population Monitor_Settings.ini
2019-01-03 02:13 - 2019-01-03 02:13 - 000000000 _ () C:\Users\Robert\AppData\Local\oobelibMkey.log
2018-07-06 08:44 - 2018-08-02 12:57 - 000002963 _ () C:\Users\Robert\AppData\Local\Perfmon.PerfmonCfg
2019-01-25 13:45 - 2019-01-25 13:45 - 000000218 _ () C:\Users\Robert\AppData\Local\recently-used.xbel
2017-01-11 18:07 - 2019-01-14 17:06 - 000007658 _ () C:\Users\Robert\AppData\Local\Resmon.ResmonCfg
2018-06-09 15:02 - 2019-02-13 12:32 - 610763776 _ () C:\Users\Robert\AppData\Local\SageThumbs.db3
2019-01-12 10:49 - 2019-01-12 10:49 - 016040448 _ () C:\Users\Robert\AppData\Local\Sync-1547318938.msi
2019-01-12 10:49 - 2019-01-12 10:49 - 000192518 _ () C:\Users\Robert\AppData\Local\Sync-1547318938.msi.log
2017-09-29 19:09 - 2017-09-29 19:09 - 000000000 _ () C:\Users\Robert\AppData\Local\{890F3F8A-F9BD-4993-A048-4AB71E9986FF}
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
Pasted here is: FRST.TXT
----------------------------
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13.02.2019
Ran by Robert (administrator) on MAIN (13-02-2019 12:41:46)
Running from C:\Users\Robert\Desktop
Loaded Profiles: Robert (Available Profiles: Robert & Administrator)
Platform: Windows 10 Pro Version 1809 17763.253 (X64) Language: English (United States)
Default browser: "C:\Program Files\Waterfox\waterfox.exe" -osint -url "%1"
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidMonitorSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Backblaze\bzserv.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
() C:\Program Files (x86)\NordVPN\nordvpn-service.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Windows\System32\snmp.exe
() C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
(Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PrecisionX_x64.exe
(IObit) C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe
(Bitsum LLC) C:\Program Files\Process Lasso\ProcessGovernor.exe
(Bitsum LLC) C:\Program Files\Process Lasso\ProcessLasso.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PrecisionXServer.exe
(EVGA Corp.) C:\Program Files (x86)\EVGA\Precision XOC\PXSW10_x64.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
(GP Software) C:\Program Files\Directory Opus\dopusrt.exe
() C:\Program Files (x86)\Backblaze\bzbui.exe
(NordVPN) C:\Program Files (x86)\NordVPN\NordVPN.exe
(Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Program Files (x86)\AudioSwitch\AudioSwitch.exe
() C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
(XRayz Software) C:\Program Files\ClipCache\clipc.exe
(Code Sector) C:\Program Files (x86)\Direct Folders\df.exe
(Code Sector Inc.) C:\Program Files (x86)\Direct Folders\df64.exe
(Intel) C:\Program Files (x86)\Intel Driver and Support Assistant\DSATray.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\natspeak.exe
(Neuber Software - www.neuber.com) C:\Program Files (x86)\Security Task Manager\SpyProtector.exe
(Carthago Software) C:\Program Files (x86)\MemInfo\meminfo.exe
() C:\Program Files (x86)\CyberPower PowerPanel Personal\PowerPanel Personal.exe
(VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Sync.com Inc.) C:\Users\Robert\AppData\Local\Programs\Sync\sync-taskbar.exe
() C:\Users\Robert\AppData\Local\Programs\Sync\sync-worker.exe
() C:\Users\Robert\AppData\Local\Programs\Sync\sync-worker.exe
() C:\Users\Robert\AppData\Local\Programs\Sync\sync-worker.exe
(NTWind Software) C:\Program Files\WindowSpace\wspace64.exe
(NTWind Software) C:\Program Files\WindowSpace\wspace32.exe
(Microsoft Corporation) C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking15\x64\dgnuiasvr_x64.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Common Files\Nuance\NaturallySpeaking15\dragonbar.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
() C:\Program Files (x86)\CyberPower PowerPanel Personal\ppped.exe
() C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Safer-Networking Ltd\Spybot Anti-Beacon\Spybot3AntiBeacon.exe
(Microsoft Corporation) C:\Program Files (x86)\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(WordWeb Software) C:\Program Files (x86)\WordWeb\wweb32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
() C:\Program Files\Everything\Everything.exe
(Ipswitch, Inc. 83 Hartwell Avenue Lexington, MA 02421) C:\Program Files (x86)\Ipswitch\WS_FTP 12\WsftpCOMHelper.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\ecmds.exe [177928 2019-01-03] (ESET, spol. s r.o. -> ESET)
HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2675176 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
HKLM\...\Run: [IAStorIcon] => c:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321096 2017-06-20] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9279520 2019-01-31] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-07-06] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [Fences] => C:\Program Files (x86)\Stardock\Fences\Fences.exe [4854200 2018-05-25] (Stardock Corporation -> Stardock Corporation) [File not signed]
HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [588360 2017-06-22] (Acronis International GmbH -> )
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [509936 2018-04-11] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5118656 2017-06-22] (Acronis International GmbH -> )
HKLM-x32\...\Run: [DSATray] => C:\Program Files (x86)\Intel Driver and Support Assistant\DsaTray.exe [137464 2018-07-30] (Intel(R) Driver & Support Assistant -> Intel)
HKLM-x32\...\Run: [Spy Protector] => C:\Program Files (x86)\Security Task Manager\SpyProtector.exe [145280 2018-07-12] (A. & M. Neuber Software -> Neuber Software - www.neuber.com)
HKLM-x32\...\Run: [WordWeb] => C:\Program Files (x86)\WordWeb\wweb32.exe [81120 2016-02-12] (WordWeb Software -> WordWeb Software)
HKLM-x32\...\Run: [CyberPower] => C:\Program Files (x86)\CyberPower PowerPanel Personal\PowerPanel Personal.exe [123392 2018-07-17] () [File not signed]
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [125872 2018-11-21] (VMware, Inc. -> VMware, Inc.)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [2075480 2013-06-24] (Flexera Software LLC -> Flexera Software LLC.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [4810224 2018-12-19] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM\...\Policies\Explorer: [ForceActiveDesktopOn] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\...\Policies\Explorer: [NoRecentDocsHistory] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\...\Policies\Explorer: [NoRecentDocsNetHood] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\...\Policies\Explorer: [NoChangeStartMenu] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\...\Policies\Explorer: [NoControlPanel] C:\Windows\System32\0 [0 2018-09-19] (CryptCATAdminCalcHashFromFileHandle failed to return cbHash, #2 -> )
HKLM\Software\Policies\Microsoft\Windows NT\SystemRestore: [DisableSR/DisableConfig] <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2018-09-14] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2018-09-14] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [Directory Opus Desktop Dblclk] => C:\Program Files\Directory Opus\dopusrt.exe [694128 2017-06-09] (GP Software -> GP Software)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [1061728 2019-02-07] (Backblaze, Inc -> )
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [NordVPN] => C:\Program Files (x86)\NordVPN\NordVPN.exe [2222032 2018-12-04] (TEFINCOM S.A. -> NordVPN)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19645800 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [2075480 2013-06-24] (Flexera Software LLC -> Flexera Software LLC.)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [Fences] => c:\program files (x86)\stardock\fences\Fences.exe [4854200 2018-05-25] (Stardock Corporation -> Stardock Corporation)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Run: [HomeAlarm] => C:\Program Files (x86)\Chameleon Clock\ChamClock.exe [709632 2007-12-11] (Softshape Development)
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoPreviewPane] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [HideSCANetwork] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [HideSCAVolume] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [DisableThumbnails] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoFileMenu] 0
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoToolbarCustomize] 1
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-18\...\Run: [Backblaze] => C:\Program Files (x86)\Backblaze\bzbui.exe [1061728 2019-02-07] (Backblaze, Inc -> )
HKLM\...\Drivers32-x32: [vidc.tscc] => C:\Windows\SysWOW64\tsccvid.dll [102400 2005-06-15] (TechSmith Corporation)
HKLM\...\Drivers32-x32: [msacm.pspgru] => C:\Windows\SysWOW64\pspgru.acm [401920 2010-03-22] (Philips Austria GmbH - Speech Processing)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.96\Installer\chrmstp.exe [2019-02-07] (Google LLC -> Google Inc.)
Lsa: [Authentication Packages] msv1_0 SshdPinAuthLsa
ShellExecuteHooks: Directory Opus Shell Execute Hook - {3CF9ECE0-1A9F-11D2-8C73-00C06C2005DE} - C:\Program Files\Directory Opus\dopuslib.dll [765808 2017-06-09] (GP Software -> GP Software)
ShellExecuteHooks-x32: Directory Opus Shell Execute Hook - {EE761688-C137-4b04-8FAB-3C9CDF0886F0} - C:\Program Files\Directory Opus\dopuslib32.dll [381296 2017-06-09] (GP Software -> GP Software)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AudioSwitch.lnk [2018-10-16]
ShortcutTarget: AudioSwitch.lnk -> C:\Program Files (x86)\AudioSwitch\AudioSwitch.exe ()
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ClipCache Pro.lnk [2019-01-10]
ShortcutTarget: ClipCache Pro.lnk -> C:\Program Files\ClipCache\clipc.exe (XRayz Software)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Direct Folders.lnk [2018-10-18]
ShortcutTarget: Direct Folders.lnk -> C:\Program Files (x86)\Direct Folders\df.exe (Code Sector)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dragon NaturallySpeaking.lnk [2018-11-04]
ShortcutTarget: Dragon NaturallySpeaking.lnk -> C:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\natspeak.exe (Nuance Communications, Inc.)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\meminfo.lnk [2018-10-16]
ShortcutTarget: meminfo.lnk -> C:\Program Files (x86)\MemInfo\meminfo.exe (Carthago Software)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\schedhlp.lnk [2018-10-16]
ShortcutTarget: schedhlp.lnk -> C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe ()
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar551.lnk [2019-02-12]
ShortcutTarget: Sidebar551.lnk -> C:\Program Files (x86)\Windows Sidebar\sidebar.exe (Microsoft Corporation)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sync.lnk [2019-01-12]
ShortcutTarget: Sync.lnk -> C:\Users\Robert\AppData\Local\Programs\Sync\sync-taskbar.exe (Sync.com Inc.)
Startup: C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wspace64.lnk [2018-10-16]
ShortcutTarget: wspace64.lnk -> C:\Program Files\WindowSpace\wspace64.exe (NTWind Software)
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\.DEFAULT\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-2536635842-542287166-2959069790-1002\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{088debab-fa3f-4522-be18-eed74e83a81a}: [NameServer] 1.1.1.1,1.0.0.1
Tcpip\..\Interfaces\{088debab-fa3f-4522-be18-eed74e83a81a}: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{2643f73e-6fcf-49ed-b1c0-243ab565a6d6}: [DhcpNameServer] 208.67.222.222 208.67.220.220
Tcpip\..\Interfaces\{65450657-b491-4d43-ac56-02632efc959c}: [DhcpNameServer] 208.67.222.222 208.67.220.220
Internet Explorer:
==================
HKU\S-1-5-21-2536635842-542287166-2959069790-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO: No Name -> {27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5} -> M:\__NEW SYSTEM\OldNewExplorer\OldNewExplorer64.dll [2017-08-16] (www.startisback.com)
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
BHO: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> c:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\x64\dgnriaie_x64.dll [2018-01-27] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_191\bin\ssv.dll [2018-10-30] ()
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-10-30] ()
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> No File
BHO-x32: No Name -> {27DD0F8B-3E0E-4ADC-A78A-66047E71ADC5} -> M:\__NEW SYSTEM\OldNewExplorer\OldNewExplorer32.dll [2017-08-16] (www.startisback.com)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
BHO-x32: Dragon Web Extension For Internet Explorer -> {609C0837-8DD3-4F9B-AAC5-446F36BC0353} -> c:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\dgnriaie.dll [2018-01-27] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\ssv.dll [2018-10-30] ()
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-10-30] ()
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
BHO-x32: ExplorerWatcher Class -> {F8A6CAA2-533D-4AED-9E05-8EB19A4021AB} -> No File
Toolbar: HKLM - TextAloud Toolbar - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Program Files (x86)\TextAloud\TAForIE64.dll [2017-07-24] (NEXTUP TECHNOLOGIES, LLC -> NextUp.com)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Toolbar: HKLM-x32 - TextAloud Toolbar - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\Program Files (x86)\TextAloud\TAForIE.dll [2017-07-24] (NEXTUP TECHNOLOGIES, LLC -> NextUp.com)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2018-06-29] (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
IE Session Restore: HKU\S-1-5-21-2536635842-542287166-2959069790-1002 -> is enabled.
Handler-x32: intu-help-qb7 - {5A03BD9D-766D-47A6-8E87-CD90F60BE245} - C:\Program Files (x86)\Intuit\QuickBooks 2014\HelpAsyncPluggableProtocol.dll [2014-12-10] (Intuit, Inc. -> Intuit, Inc.)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2019-01-24] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\SysWOW64\mscoree.dll [2018-09-14] (Microsoft Windows -> Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File
Edge:
======
Edge Extension: (Adblock Plus) -> 10_EyeoGmbHAdblockPlus_d55gg7py3s0m0 => C:\Program Files\WindowsApps\EyeoGmbH.AdblockPlus_0.9.9.0_neutral__d55gg7py3s0m0 [2019-01-16]
Edge Extension: (Ghostery – Privacy Ad Blocker) -> EdgeExtension_GhosteryGhostery_kzkqe0pn505dg => C:\Program Files\WindowsApps\Ghostery.Ghostery_8.1.0.0_neutral__kzkqe0pn505dg [2019-01-16]
FireFox:
========
FF DefaultProfile: m2jh29d5.default
FF DefaultProfile: 01gmxgwq.Normal
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Thinstall\RegCleanPro\%AppData%\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 [not found] <==== ATTENTION
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Thinstall\RegCleanPro\%AppData%\Mozilla\Firefox\Profiles\01gmxgwq.Normal [not found] <==== ATTENTION
FF DefaultProfile: i4a2hsup.Default-1504416014746
FF DefaultProfile: qnjlgicb.default
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default [2019-02-13]
FF Homepage: Waterfox\Profiles\m2jh29d5.default -> hxxps://www.startpage.com/
FF NewTab: Waterfox\Profiles\m2jh29d5.default -> www.startpage.com
FF Session Restore: Waterfox\Profiles\m2jh29d5.default -> is enabled.
FF Extension: (Amazon Assistant for Firefox) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\abb@amazon.com.xpi [2018-05-09]
FF Extension: (AIO Search) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\ASToolbar@aiosearch.com.xpi [2018-01-22]
FF Extension: (New Add-on Bar) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\ausaddonbar@teo.pl.xpi [2018-11-04] [Legacy]
FF Extension: (Bookmarks Favicon Images) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\BookmarksFaviconImages@LarrysComputer.xpi [2018-11-03] [Legacy]
FF Extension: (Bookmarks Folder Images) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\BookmarksFolderImages@LarrysComputer.xpi [2018-10-06] [Legacy]
FF Extension: (Bookmarks Title Styles) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\BookmarksTitleStyles@LarrysComputer.xpi [2018-11-03] [Legacy]
FF Extension: (Classic Reload-Stop-Go Button) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\crsg@ArisT2_Noia4dev.xpi [2018-11-03] [Legacy]
FF Extension: (Classic Toolbar Buttons) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2018-07-06] [Legacy]
FF Extension: (Dragon Professional Web Extension) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\dgnria_pro.firefox@nuance.com.xpi [2018-10-08]
FF Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\firefox@ghostery.com.xpi [2019-02-01]
FF Extension: (SimilarWeb - Traffic Rank & Website Analysis) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\FirefoxAddon@similarWeb.com.xpi [2018-11-03]
FF Extension: (Webmail Ad Blocker) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\gmailnoads@mywebber.com.xpi [2019-01-03]
FF Extension: (Who stole my pictures?) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\images@wink.su.xpi [2018-04-02]
FF Extension: (PriceBlink Coupons and Price Comparison) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\info@priceblink.com.xpi [2019-01-25]
FF Extension: (Terms of Service; Didn’t Read) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid0-3GUEt1r69sQNSrca5p8kx9Ezc3U@jetpack.xpi [2018-08-20]
FF Extension: (Visited) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid0-xGZYdxpAkROWMUMfWKINyrXigBA@jetpack.xpi [2018-01-27] [Legacy]
FF Extension: (YouTube™ Flash® Player) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi [2018-10-03]
FF Extension: (Media Converter and Muxer) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid1-kps5PrGBNtzSLQ@jetpack.xpi [2018-02-12] [Legacy]
FF Extension: (Privacy Badger) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2018-09-20]
FF Extension: (Free Memory) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\jid1-n85lxPv1NAWVTQ@jetpack.xpi [2018-11-17] [Legacy]
FF Extension: (Lightweight Themes Manager) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\lwthemes-manager@loucypher.xpi [2018-10-03] [Legacy]
FF Extension: (Memory Restart) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\memoryrestart@teamextension.com.xpi [2018-11-17] [Legacy]
FF Extension: (Menu Icons Plus) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\menuiconsplus@codedawn.com.xpi [2018-05-07] [Legacy]
FF Extension: (Saved Password Editor) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\savedpasswordeditor@daniel.dawson.xpi [2018-11-03] [Legacy]
FF Extension: (Tab Session Manager) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\Tab-Session-Manager@sienori.xpi [2019-02-08]
FF Extension: (The Addon Bar (restored)) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\the-addon-bar@GeekInTraining-GiT.xpi [2018-11-03] [Legacy]
FF Extension: (TinEye Reverse Image Search) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\tineye@ideeinc.com.xpi [2018-10-04]
FF Extension: (TrackMeNot) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\trackmenot@mrl.nyu.edu.xpi [2018-11-03]
FF Extension: (uBlock Origin) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\uBlock0@raymondhill.net.xpi [2019-02-05]
FF Extension: (uMatrix) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\uMatrix@raymondhill.net.xpi [2019-01-03]
FF Extension: (Vertical Toolbar) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\verticaltoolbar@xuldev.org.xpi [2018-11-03] [Legacy]
FF Extension: (Session Manager) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2018-11-03] [Legacy]
FF Extension: (Multirow Bookmarks Toolbar Plus) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{4c7097f7-08f2-4ef2-9b9f-f95fa4cbb064}.xpi [2018-05-19] [Legacy]
FF Extension: (No Coin - Block miners on the web!) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{5657c026-efc3-4860-b43b-16e4eaa8a9aa}.xpi [2019-01-24]
FF Extension: (Google™ Shortcuts - MSG_cj_i18n_01720) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2019-02-12]
FF Extension: (Download Status Bar) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2018-09-08] [Legacy]
FF Extension: (Bulk Media Downloader) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{72b2e02b-3a71-4895-886c-fd12ebe36ba3}.xpi [2018-02-12]
FF Extension: (blockcoinm) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{74b0af75-8791-44e2-95a6-7f0ab94143ec}.xpi [2019-01-26]
FF Extension: (Download Statusbar) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{76faaba6-3aa1-47a4-bf40-90aa2505e79c}.xpi [2019-01-03]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2019-01-26]
FF Extension: (Video DownloadHelper) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2018-01-22]
FF Extension: (In My Pocket) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{cd7e22de-2e34-40f0-aeff-cec824cbccac}.xpi [2019-01-03]
FF Extension: (OFFMP4 - Best Video Download Helper) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{cf9bb404-04a5-4329-8764-aae71359f0f8}.xpi [2019-01-22]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-01-23]
FF Extension: (Tab Mix Plus) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2018-09-05] [Legacy]
FF Extension: (SnapTube MP3 for YouTube Music Download) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{e4b3d1b4-3bb2-4df7-ad1b-77534bac5780}.xpi [2018-12-01]
FF Extension: (YouTube Flash Video Player) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2018-05-06]
FF Extension: (Theme Font & Size Changer) - C:\Users\Robert\AppData\Roaming\Waterfox\Profiles\m2jh29d5.default\Extensions\{f69e22c7-bc50-414a-9269-0f5c344cd94c}.xpi [2018-11-03]
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 [2019-02-11]
FF user.js: detected! => C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\user.js [2018-11-03]
FF Homepage: Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 -> hxxps://www.startpage.com/
FF NewTab: Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 -> www.startpage.com
FF NetworkProxy: Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 -> type", 0
FF Session Restore: Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746 -> is enabled.
FF Extension: (Amazon Assistant for Firefox) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\abb@amazon.com.xpi [2018-05-09]
FF Extension: (AIO Search) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\ASToolbar@aiosearch.com.xpi [2018-01-22]
FF Extension: (New Add-on Bar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\ausaddonbar@teo.pl.xpi [2018-11-04] [Legacy]
FF Extension: (Bookmarks Favicon Images) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\BookmarksFaviconImages@LarrysComputer.xpi [2018-11-04] [Legacy]
FF Extension: (Bookmarks Folder Images) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\BookmarksFolderImages@LarrysComputer.xpi [2018-10-06] [Legacy]
FF Extension: (Bookmarks Title Styles) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\BookmarksTitleStyles@LarrysComputer.xpi [2018-11-04] [Legacy]
FF Extension: (Classic Toolbar Buttons) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2018-07-06] [Legacy]
FF Extension: (Dragon Professional Web Extension) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\dgnria_pro.firefox@nuance.com.xpi [2018-10-08]
FF Extension: (Ghostery – Privacy Ad Blocker) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\firefox@ghostery.com.xpi [2019-02-05]
FF Extension: (Webmail Ad Blocker) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\gmailnoads@mywebber.com.xpi [2019-01-13]
FF Extension: (Who stole my pictures?) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\images@wink.su.xpi [2018-04-02]
FF Extension: (PriceBlink Coupons and Price Comparison) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\info@priceblink.com.xpi [2019-01-26]
FF Extension: (Terms of Service; Didn’t Read) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid0-3GUEt1r69sQNSrca5p8kx9Ezc3U@jetpack.xpi [2018-08-20]
FF Extension: (Visited) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid0-xGZYdxpAkROWMUMfWKINyrXigBA@jetpack.xpi [2018-01-27] [Legacy]
FF Extension: (YouTube™ Flash® Player) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid1-HAV2inXAnQPIeA@jetpack.xpi [2018-10-03]
FF Extension: (Media Converter and Muxer) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid1-kps5PrGBNtzSLQ@jetpack.xpi [2018-02-12] [Legacy]
FF Extension: (Privacy Badger) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2019-02-10]
FF Extension: (Free Memory) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\jid1-n85lxPv1NAWVTQ@jetpack.xpi [2018-11-18] [Legacy]
FF Extension: (Lightweight Themes Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\lwthemes-manager@loucypher.xpi [2018-10-03] [Legacy]
FF Extension: (Menu Icons Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\menuiconsplus@codedawn.com.xpi [2018-05-07] [Legacy]
FF Extension: (Tab Session Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\Tab-Session-Manager@sienori.xpi [2019-02-09]
FF Extension: (TinEye Reverse Image Search) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\tineye@ideeinc.com.xpi [2018-10-04]
FF Extension: (uBlock Origin) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\uBlock0@raymondhill.net.xpi [2019-02-05]
FF Extension: (uMatrix) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\uMatrix@raymondhill.net.xpi [2019-01-13]
FF Extension: (Session Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2018-11-04] [Legacy]
FF Extension: (Multirow Bookmarks Toolbar Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{4c7097f7-08f2-4ef2-9b9f-f95fa4cbb064}.xpi [2018-05-19] [Legacy]
FF Extension: (No Coin - Block miners on the web!) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{5657c026-efc3-4860-b43b-16e4eaa8a9aa}.xpi [2019-01-26]
FF Extension: (Google™ Shortcuts - All services at a glance) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2019-01-31]
FF Extension: (Download Status Bar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2018-09-08] [Legacy]
FF Extension: (Bulk Media Downloader) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{72b2e02b-3a71-4895-886c-fd12ebe36ba3}.xpi [2018-02-12]
FF Extension: (blockcoinm) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{74b0af75-8791-44e2-95a6-7f0ab94143ec}.xpi [2019-01-26]
FF Extension: (Download Statusbar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{76faaba6-3aa1-47a4-bf40-90aa2505e79c}.xpi [2019-01-13]
FF Extension: (Easy Youtube Video Downloader Express) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2019-01-26]
FF Extension: (Video DownloadHelper) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2018-01-22]
FF Extension: (In My Pocket) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{cd7e22de-2e34-40f0-aeff-cec824cbccac}.xpi [2019-01-13]
FF Extension: (OFFMP4 - Best Video Download Helper) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{cf9bb404-04a5-4329-8764-aae71359f0f8}.xpi [2019-01-26]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-01-26]
FF Extension: (Tab Mix Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2018-09-05] [Legacy]
FF Extension: (SnapTube MP3 for YouTube Music Download) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{e4b3d1b4-3bb2-4df7-ad1b-77534bac5780}.xpi [2018-12-01]
FF Extension: (YouTube Flash Video Player) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\i4a2hsup.Default-1504416014746\Extensions\{f3bd3dd2-2888-44c5-91a2-2caeb33fb898}.xpi [2018-05-06]
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal [2019-02-11]
FF user.js: detected! => C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\user.js [2018-11-03]
FF Homepage: Mozilla\Firefox\Profiles\01gmxgwq.Normal -> hxxp://www.google.com/
FF NewTab: Mozilla\Firefox\Profiles\01gmxgwq.Normal -> hxxp://www.google.com
FF NetworkProxy: Mozilla\Firefox\Profiles\01gmxgwq.Normal -> type", 4
FF Session Restore: Mozilla\Firefox\Profiles\01gmxgwq.Normal -> is enabled.
FF Extension: (Grammarly for Firefox) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\87677a2c52b84ad3a151a4a72f5bd3c4@jetpack.xpi [2017-12-24]
FF Extension: (HLS Stream Detector) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\@m3u8link.xpi [2017-09-21] [Legacy]
FF Extension: (AIO Search) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\ASToolbar@aiosearch.com.xpi [2017-08-19]
FF Extension: (New Add-on Bar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\ausaddonbar@teo.pl.xpi [2017-08-17] [Legacy]
FF Extension: (Bookmarks Favicon Images) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\BookmarksFaviconImages@LarrysComputer.xpi [2017-11-15] [Legacy]
FF Extension: (Bookmarks Title Styles) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\BookmarksTitleStyles@LarrysComputer.xpi [2017-11-15] [Legacy]
FF Extension: (Add-on Compatibility Reporter) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\compatibility@addons.mozilla.org.xpi [2017-07-18] [Legacy]
FF Extension: (Classic Reload-Stop-Go Button) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\crsg@ArisT2_Noia4dev.xpi [2017-09-17] [Legacy]
FF Extension: (Classic Toolbar Buttons) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\CSTBB@NArisT2_Noia4dev.xpi [2017-12-24] [Legacy]
FF Extension: (Dragon Web Extension) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\dgnria2@nuance.com.xpi [2017-12-09] [Legacy]
FF Extension: (Exif Viewer) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\exif_viewer@mozilla.doslash.org.xpi [2017-12-30]
FF Extension: (Ghostery) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\firefox@ghostery.com.xpi [2017-12-30]
FF Extension: (SimilarWeb - Traffic Rank & Website Analysis) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\FirefoxAddon@similarWeb.com.xpi [2017-12-24]
FF Extension: (Webmail Ad Blocker) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\gmailnoads@mywebber.com.xpi [2017-12-24]
FF Extension: (PriceBlink Coupons and Price Comparison) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\info@priceblink.com.xpi [2017-11-16]
FF Extension: (Turbo Download Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid0-dsq67mf5kjjhiiju2dfb6kk8dfw@jetpack.xpi [2017-02-28] [Legacy]
FF Extension: (Media Converter and Muxer) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid1-kps5PrGBNtzSLQ@jetpack.xpi [2017-05-30] [Legacy]
FF Extension: (Privacy Badger) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2017-12-24]
FF Extension: (igshortcuts) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid1-SVJwkBGCTt4PyQ@jetpack.xpi [2017-08-21]
FF Extension: (visited_enabler) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\jid1-yDnsmkBoiRtgNA@jetpack.xpi [2017-07-06] [Legacy]
FF Extension: (Master Password+) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\masterpasswordtimeoutplus@vano [2018-01-14] [Legacy]
FF Extension: (Saved Password Editor) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\savedpasswordeditor@daniel.dawson.xpi [2017-11-16] [Legacy]
FF Extension: (StickyNotes) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\sticky@filenamezero.dip.jp.xpi [2017-12-30]
FF Extension: (TinEye Reverse Image Search) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\tineye@ideeinc.com.xpi [2017-06-28]
FF Extension: (TrackMeNot) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\trackmenot@mrl.nyu.edu.xpi [2017-12-24]
FF Extension: (uBlock Origin) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\uBlock0@raymondhill.net.xpi [2017-12-24]
FF Extension: (uMatrix) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\uMatrix@raymondhill.net.xpi [2017-12-24]
FF Extension: (Vertical Toolbar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\verticaltoolbar@xuldev.org.xpi [2017-11-16] [Legacy]
FF Extension: (Flagfox) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2017-11-16] [Legacy]
FF Extension: (Session Manager) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2017-11-15] [Legacy]
FF Extension: (Extension Options Menu) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{1feca320-6b4d-11df-a08a-0800200c9a66}.xpi [2017-09-02] [Legacy]
FF Extension: (Multirow Bookmarks Toolbar Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{4c7097f7-08f2-4ef2-9b9f-f95fa4cbb064}.xpi [2017-09-07] [Legacy]
FF Extension: (EPUBReader) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}.xpi [2017-08-01]
FF Extension: (Google™ Shortcuts - All services at a glance) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi [2017-12-24]
FF Extension: (Download Status Bar) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2017-11-15] [Legacy]
FF Extension: (Bulk Media Downloader) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{72b2e02b-3a71-4895-886c-fd12ebe36ba3}.xpi [2017-11-16]
FF Extension: (Themes Menu) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{84625510-7e5d-11e0-a411-0800200c9a66}.xpi [2017-05-31] [Legacy]
FF Extension: (More Tools Menu) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{9a7a67d3-3048-47fb-acde-d0f7ae51f86a}.xpi [2017-07-19] [Legacy]
FF Extension: (Video DownloadHelper) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-11-15]
FF Extension: (Adblock Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-01-22]
FF Extension: (Tab Mix Plus) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2017-11-15] [Legacy]
FF Extension: (Theme Font & Size Changer) - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\01gmxgwq.Normal\Extensions\{f69e22c7-bc50-414a-9269-0f5c344cd94c}.xpi [2017-11-15]
FF ProfilePath: C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default [2018-06-09]
FF Extension: (Czech (CZ) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-cs@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Deutsch (DE) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-de@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (English (US) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-en-US@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Español (España) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-es-ES@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Finnish Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-fi@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Français Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-fr@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Galego (España) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-gl@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Hebrew (IL) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-he@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Magyar (HU) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-hu@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Italiano (IT) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-it@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Japanese Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-ja@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Korean (KR) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-ko@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Nederlands (NL) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-nl@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Polski Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-pl@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Russian (RU) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-ru@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Slovenski jezik Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-sl@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (српски (sr) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-sr@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Svenska (SE) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-sv-SE@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Chinese Simplified (zh-CN) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-zh-CN@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF Extension: (Traditional Chinese (zh-TW) Language Pack) - C:\Users\Robert\AppData\Roaming\Disruptive Innovations SARL\BlueGriffon\Profiles\qnjlgicb.default\Extensions\langpack-zh-TW@bluegriffon.org.xpi [2018-06-09] [Legacy] [not signed]
FF HKLM\...\Firefox\Extensions: [{5e1bc830-4746-11e5-b970-0800200c9a66}] - C:\Program Files (x86)\TextAloud\TAForFirefox.xpi
FF Extension: (TextAloud for Firefox) - C:\Program Files (x86)\TextAloud\TAForFirefox.xpi [2018-03-04]
FF HKLM\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Extension: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi [2018-10-19]
FF HKLM-x32\...\Firefox\Extensions: [{5e1bc830-4746-11e5-b970-0800200c9a66}] - C:\Program Files (x86)\TextAloud\TAForFirefox.xpi
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.17@acrobat.adobe.com] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn\WebExtn\signed_extn\adobe_acrobat-1.0-windows.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_114.dll [2019-01-11] ()
FF Plugin: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-10-30] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-10-30] (Oracle Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2019-01-24] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-25] (Adobe Systems)
FF Plugin: nuance.com/DgnRia2_x86_64 -> c:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\x64\npDgnRia2_x64.dll [2018-01-27] (Nuance Communications, Inc.)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_114.dll [2019-01-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-10-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-10-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2019-01-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2019-01-11] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2019-01-11] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-01-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2019-01-03] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.3 -> C:\Program Files (x86)\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VLC\npvlc.dll [2018-08-09] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2018-12-19] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-25] (Adobe Systems)
FF Plugin-x32: nuance.com/DgnRia2 -> c:\Program Files (x86)\Nuance\NaturallySpeaking15\Program\npDgnRia2.dll [2018-01-27] (Nuance Communications, Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default [2019-01-30]
CHR Extension: (Slides) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-14]
CHR Extension: (Docs) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-14]
CHR Extension: (Google Drive) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-14]
CHR Extension: (YouTube) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-14]
CHR Extension: (uBlock Origin) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2018-08-28]
CHR Extension: (Sheets) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-14]
CHR Extension: (Google Docs Offline) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-08-28]
CHR Extension: (TextAloud for Chrome) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\obcnimnkkpdkbfnnoagjogdollcfnidj [2018-08-28]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2018-08-28]
CHR Extension: (Gmail) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-14]
CHR Extension: (Chrome Media Router) - C:\Users\Robert\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-19]
CHR Profile: C:\Users\Robert\AppData\Local\Google\Chrome\User Data\System Profile [2018-10-06]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [obcnimnkkpdkbfnnoagjogdollcfnidj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-25] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2917864 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2709480 2018-12-13] (Adobe Systems Incorporated -> Adobe Systems, Incorporated)
S3 AndServMgr; c:\Program Files\AMI\DuOS\AndServMgr.exe [86944 2018-03-07] (American Megatrends Inc -> American Megatrends Inc.)
R2 ApHidMonitorService; C:\Program Files\Apoint2K\HidMonitorSvc.exe [117280 2017-02-08] (ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\4.00.01\atkexComSvc.exe [382424 2018-01-04] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
S3 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe [954648 2015-05-07] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-04-23] (ASUSTeK Computer Inc. -> ) [File not signed]
S3 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\2.00.33\AsusFanControlService.exe [1340376 2017-12-04] (ASUSTeK Computer Inc. -> ASUSTeK Computer Inc.)
R2 bzserv; C:\Program Files (x86)\Backblaze\bzserv.exe [543584 2019-02-07] (Backblaze, Inc -> )
S3 ChamClock Set Time Service for Vista; C:\Program Files (x86)\Chameleon Clock\settime.exe [58880 2007-06-27] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9677472 2018-12-30] (Microsoft Corporation -> Microsoft Corporation)
R2 DragonLoggerService; C:\Program Files (x86)\Common Files\Nuance\loggerservice.exe [166288 2018-01-27] (Nuance Communications, Inc. -> Nuance Communications, Inc.)
R2 DSAService; C:\Program Files (x86)\Intel Driver and Support Assistant\DSAService.exe [23288 2018-07-30] (Intel(R) Driver & Support Assistant -> Intel)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2302160 2019-01-03] (ESET, spol. s r.o. -> ESET)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (SEIKO EPSON Corporation -> Seiko Epson Corporation)
S3 Everything; C:\Program Files\Everything\Everything.exe [2199656 2018-02-08] (David Carpenter -> )
S4 GladFileMonSvc; C:\Program Files (x86)\Nuance\Nuance Cloud Connector\GladFileMonSvc.exe [29552 2011-07-26] (Gladinet, Inc. -> Gladinet, INC)
R2 IAStorDataMgrSvc; c:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2017-06-20] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S4 ICEsoundService; C:\WINDOWS\system32\ICEsoundService64.exe [807808 2019-01-31] (ICEpower a/s -> ICEpower)
S3 Intel(R) SUR QC SAM; C:\Program Files\Intel\SUR\QUEENCREEK\Updater\bin\IntelSoftwareAssetManagerService.exe [18168 2017-07-13] (Intel(R) Software Asset Manager -> Intel Corporation)
S4 mmsminisrv; c:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4795288 2017-02-13] (Acronis International GmbH -> Acronis International GmbH)
S3 mobile_backup_server; c:\Program Files (x86)\Common Files\Acronis\MobileBackupServer\mobile_backup_server.exe [2908352 2017-01-06] (Acronis International GmbH -> Acronis International GmbH)
S3 mobile_backup_status_server; c:\Program Files (x86)\Acronis\TrueImageHome\mobile_backup_status_server.exe [1617520 2017-06-22] (Acronis International GmbH -> )
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [233456 2017-07-03] (Netgear Incorporated -> NETGEAR)
R2 nordvpn-service; C:\Program Files (x86)\NordVPN\nordvpn-service.exe [184784 2018-12-04] (TEFINCOM S.A. -> )
S3 Oasis2Service (Intel(R) Device Advisor); C:\Program Files (x86)\DDNi\Oasis2Service (Intel Device Advisor)\Oasis2Service.exe [72472 2016-07-30] (Digital Delivery Networks, Inc. -> Digital Delivery Networks, Inc.)
R2 PowerPanel Personal Service; C:\Program Files (x86)\CyberPower PowerPanel Personal\ppped.exe [11264 2018-07-17] () [File not signed]
S4 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2014-12-10] (Intuit) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2013-10-10] (Intuit Inc.) [File not signed]
S4 QBVSS; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [1248256 2013-08-19] (Intuit Inc.) [File not signed]
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5381128 2019-01-09] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [745664 2016-01-11] (@ByELDI -> @ByELDI) [File not signed]
R2 SNMP; C:\WINDOWS\System32\snmp.exe [53248 2018-10-12] (Microsoft Windows -> Microsoft Corporation)
R2 SNMP; C:\WINDOWS\SysWOW64\snmp.exe [46592 2018-10-12] (Microsoft Windows -> Microsoft Corporation)
S3 SSDkeeper; C:\Program Files\Condusiv Technologies\SSDkeeper\SkService.exe [3112648 2016-12-23] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
S3 sshd; C:\WINDOWS\System32\OpenSSH\sshd.exe [974848 2019-01-04] (Microsoft Windows -> )
S3 SshdBroker; C:\WINDOWS\System32\SshdBroker.dll [289280 2018-10-12] (Microsoft Windows -> Microsoft Corporation)
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-20] (DEVGURU CO LTD -> DEVGURU Co., LTD.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11665136 2019-01-16] (TeamViewer GmbH -> TeamViewer GmbH)
S3 vmware-converter-agent; C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe [503512 2016-02-09] (VMware, Inc. -> VMware, Inc.)
S3 vmware-converter-server; C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [503512 2016-02-09] (VMware, Inc. -> VMware, Inc.)
S3 vmware-converter-worker; C:\Program Files (x86)\VMware\VMware vCenter Converter Standalone\vmware-converter.exe [503512 2016-02-09] (VMware, Inc. -> VMware, Inc.)
R2 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [15446960 2018-11-21] (VMware, Inc. -> )
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3830488 2018-09-14] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [110944 2018-09-14] (Microsoft Corporation -> Microsoft Corporation)
S3 XTU3SERVICE; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe [19192 2015-09-21] (Intel(R) Software -> Intel(R) Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-22] (ASUSTeK Computer Inc. -> ASUSTek Computer Inc.)
S3 AlpsHidSmb; C:\WINDOWS\system32\DRIVERS\ApSmbDrv.sys [113728 2017-02-08] (ALPS ELECTRIC CO., LTD. -> Alps Electric Co., Ltd.)
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [98848 2017-11-03] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
S3 ampa; C:\WINDOWS\system32\ampa.sys [38320 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 ampa; C:\WINDOWS\SysWOW64\ampa.sys [38320 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
R3 AmUStor; C:\WINDOWS\system32\drivers\AmUStor.SYS [109504 2019-01-31] (Alcorlink Corp. -> )
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-08] (ASUSTeK Computer Inc. -> )
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2014-02-24] (ASUSTeK Computer Inc. -> )
S3 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv.sys [303712 2018-11-01] (Bluestack Systems, Inc. -> Bluestack System Inc. )
S3 bmdrvr; C:\Windows\SysWow64\drivers\bmdrvr.sys [75992 2016-02-09] (VMware, Inc. -> VMware, Inc.)
S3 BtHidBus; C:\WINDOWS\System32\Drivers\BtHidBus.sys [25056 2011-12-21] (IVT CORPORATION -> IVT Corporation.)
S3 btnetBUs; C:\WINDOWS\System32\Drivers\btnetBus.sys [31968 2011-12-21] (IVT CORPORATION -> IVT Corporation.)
S3 csravrcp; C:\WINDOWS\System32\drivers\csravrcp.sys [26304 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 CsrBthAudioHF; C:\WINDOWS\system32\DRIVERS\CsrBthAudioHF.sys [39120 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 CsrBtPort; C:\WINDOWS\system32\DRIVERS\CsrBtPort.sys [2784968 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrhfgcc; C:\WINDOWS\System32\drivers\csrhfgcc.sys [38080 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrpan; C:\WINDOWS\System32\drivers\csrpan.sys [39616 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrserial; C:\WINDOWS\system32\DRIVERS\csrserial.sys [61128 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusb; C:\WINDOWS\System32\Drivers\csrusb.sys [47296 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csrusbfilter; C:\WINDOWS\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 csr_bthav; C:\WINDOWS\system32\drivers\csrbthav.sys [99520 2012-03-22] (Cambridge Silicon Radio Ltd. -> Cambridge Silicon Radio Limited)
S3 ddmdrv; C:\WINDOWS\system32\ddmdrv.sys [35760 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 ddmdrv; C:\WINDOWS\SysWOW64\ddmdrv.sys [33200 2016-12-27] (CHENGDU AOMEI Tech Co., Ltd. -> )
S3 DFX11_1; C:\WINDOWS\system32\drivers\dfx11_1x64.sys [28008 2017-06-19] (Power Technology -> Windows (R) Win 7 DDK provider)
S3 DFX12; C:\WINDOWS\system32\drivers\dfx12x64.sys [39048 2017-06-19] (Power Technology -> Windows (R) Win 7 DDK provider)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2018-10-08] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 DKDFM; C:\WINDOWS\System32\drivers\DKDFM.sys [41744 2013-05-06] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
S3 DKRtWrt; C:\Windows\system32\drivers\DKRtWrt.sys [48792 2016-01-28] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
R0 DKTLFSMF; C:\WINDOWS\System32\drivers\DKTLFSMF.sys [119536 2014-04-14] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies)
S3 DrvAgent64; C:\WINDOWS\SysWOW64\Drivers\DrvAgent64.SYS [22200 2018-05-24] (eSupport.com, Inc. -> Phoenix Technologies)
R1 DuoVMDrv; C:\WINDOWS\system32\DRIVERS\DuoVMDrv.sys [246720 2016-05-10] (American Megatrends Inc. -> American Megatrends Inc.)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [143448 2018-11-08] (ESET, spol. s r.o. -> ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [107896 2018-11-08] (ESET, spol. s r.o. -> ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [15872 2018-02-15] (Microsoft Windows Early Launch Anti-malware Publisher -> ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [188832 2018-11-08] (ESET, spol. s r.o. -> ESET)
S4 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [50144 2018-11-08] (ESET, spol. s r.o. -> ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [82304 2018-11-08] (ESET, spol. s r.o. -> ESET)
S1 EpfwLWF; C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys [44632 2014-08-18] (ESET, spol. s r.o. -> ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [109864 2018-11-08] (ESET, spol. s r.o. -> ESET)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [34496 2018-10-18] (CHENGDU YIWO Tech Development Co., Ltd. -> )
R0 EPMVolFlt; C:\WINDOWS\System32\drivers\EPMVolFlt.sys [30416 2018-10-18] (CHENGDU YIWO Tech Development Co., Ltd. -> Windows (R) Codename Longhorn DDK provider)
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [181160 2018-08-08] (ESET, spol. s r.o. -> ESET)
S3 ETDSMBus; C:\WINDOWS\System32\drivers\ETDSMBus.sys [31816 2018-10-08] (ELAN MICROELECTRONICS CORPORATION -> ELAN Microelectronic Corp.)
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10848 2018-10-24] (CHENGDU YIWO Tech Development Co., Ltd. -> ) [File not signed]
S3 EverestDriver; M:\__NEW SYSTEM\Everest Ultimate_5.5\EVEREST Ultimate Edition 5.50.2194 Beta ML_Portable\kerneld.amd64 [26752 2010-06-17] (LAVALYS -> )
R0 file_tracker; C:\WINDOWS\System32\DRIVERS\file_tracker.sys [378712 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
S3 FlashBoot; C:\WINDOWS\System32\drivers\FlashBoot.sys [17616 2014-04-03] (Challenger Backup Solutions, LLC -> Challenger Backup Solutions, LLC)
R0 hswultpep; C:\WINDOWS\System32\drivers\hswultpep.sys [62968 2013-02-08] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2018-10-07] (Martin Malik - REALiX -> REALiX(tm))
R0 iaStorAC; C:\WINDOWS\System32\drivers\iaStorAC.sys [967696 2018-10-08] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R2 iocbios2; C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [30224 2015-09-21] (Intel(R) Software -> Intel Corporation)
S3 IvtBtBUs; C:\WINDOWS\System32\Drivers\IvtBtBus.sys [27016 2010-04-06] (IVT SOFTWARE TECHNOLOGY Inc. -> IVT Corporation.)
S3 NPF; C:\WINDOWS\System32\drivers\npf.sys [36600 2013-02-28] (Riverbed Technology, Inc. -> Riverbed Technology, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5db32447b43ce666\nvlddmkm.sys [20461984 2019-01-11] (NVIDIA Corporation -> NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [70024 2018-10-01] (NVIDIA Corporation -> NVIDIA Corporation)
U5 PROCMON24; C:\Windows\System32\Drivers\PROCMON24.sys [93960 2019-02-06] (Microsoft Windows Hardware Compatibility Publisher -> Sysinternals - www.sysinternals.com)
S3 ptun0901; C:\WINDOWS\System32\drivers\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project) [File not signed]
R0 PxHlpa64; C:\WINDOWS\System32\drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation -> Corel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1139848 2019-01-31] (Realtek Semiconductor Corp. -> Realtek )
S3 RTCore64; C:\Program Files (x86)\RMClock\RTCore64.sys [7168 2005-05-25] () [File not signed]
R0 secnvme; C:\WINDOWS\System32\drivers\secnvme.sys [134120 2018-02-13] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd)
R2 Sentinel64; C:\WINDOWS\System32\Drivers\Sentinel64.sys [145448 2008-07-11] (SafeNet, Inc. -> SafeNet, Inc.)
R3 Serial; C:\WINDOWS\system32\DRIVERS\wdfserial.sys [80664 2015-03-06] (LG Electronics Inc. -> LG Electronics Inc.)
R0 SmartDefragDriver; C:\WINDOWS\System32\Drivers\SmartDefragDriver.sys [30744 2017-03-09] (IObit Information Technology -> IObit)
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [27136 2016-04-21] (The OpenVPN Project) [File not signed]
R3 tapnordvpn; C:\WINDOWS\System32\drivers\tapnordvpn.sys [84432 2017-03-26] (TEFINCOM S.A. -> The OpenVPN Project)
S3 tbhsd; C:\WINDOWS\system32\drivers\tbhsd.sys [57648 2019-01-11] (Audials AG -> RapidSolution Software AG)
R1 tcefs; C:\Windows\system32\drivers\tcefs.sys [26776 2015-08-18] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies Corporation)
R0 tcesd; C:\WINDOWS\System32\drivers\tcesd.sys [238320 2016-07-19] (CONDUSIV TECHNOLOGIES -> Condusiv Technologies Corporation)
R0 tib; C:\WINDOWS\System32\DRIVERS\tib.sys [1310552 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R2 tib_mounter; C:\WINDOWS\system32\DRIVERS\tib_mounter.sys [213336 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
S3 tnd; C:\WINDOWS\system32\DRIVERS\tnd.sys [690520 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R3 TotRec8; C:\WINDOWS\system32\drivers\TotRec8.sys [126080 2015-10-20] (High Criteria Inc -> High Criteria inc.)
R1 UimBus; C:\WINDOWS\System32\drivers\uimbus.sys [108896 2017-09-12] (Paragon Software GmbH -> Paragon Software GmbH)
R1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [25904 2015-11-10] (Paragon Software GmbH -> )
R1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [701360 2015-11-10] (Paragon Software GmbH -> )
R3 USBPcap; C:\WINDOWS\system32\DRIVERS\USBPcap.sys [50224 2017-08-20] (Tomasz Moń -> USBPcap)
R1 VBoxNetAdp; C:\WINDOWS\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-01-16] (Oracle Corporation -> Oracle Corporation)
R1 VBoxNetLwf; C:\WINDOWS\system32\DRIVERS\VBoxNetLwf.sys [205440 2017-01-16] (Oracle Corporation -> Oracle Corporation)
R2 virtual_file; C:\WINDOWS\System32\DRIVERS\virtual_file.sys [324952 2018-08-01] (ACRONIS INTERNATIONAL GMBH -> Acronis International GmbH)
R1 vmkbd3; C:\WINDOWS\system32\DRIVERS\vmkbd.sys [52288 2016-11-11] (VMware, Inc. -> VMware, Inc.)
R0 vsock; C:\WINDOWS\System32\DRIVERS\vsock.sys [92040 2018-06-22] (VMware, Inc. -> VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [35032 2016-02-09] (VMware, Inc. -> VMware, Inc.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46584 2018-09-14] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [340008 2018-09-14] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [61992 2018-09-14] (Microsoft Windows -> Microsoft Corporation)
R2 WinRing0_1_2_0; C:\Program Files (x86)\EVGA\Precision XOC\WinRing0\WinRing0x64.sys [14536 2015-10-20] (EVGA -> OpenLibSys.org)
S3 AscFileFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscFileFilter.sys [X]
S3 AscRegistryFilter; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\win10_amd64\AscRegistryFilter.sys [X]
S3 cpuz143; \??\C:\WINDOWS\temp\cpuz143\cpuz143_x64.sys [X]
S3 iobit_monitor_server; \??\C:\Program Files (x86)\IObit\Advanced SystemCare\drivers\Monitor_win10_x64.sys [X]
S4 nvvhci; \SystemRoot\System32\drivers\nvvhci.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One month (created) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-02-13 12:41 - 2019-02-13 12:42 - 000081067 _ C:\Users\Robert\Desktop\FRST.txt
2019-02-13 12:35 - 2019-02-13 12:35 - 002433536 _ (Farbar) C:\Users\Robert\Desktop\FRST64.exe
2019-02-13 02:59 - 2019-02-13 11:59 - 000000130 C:\Users\Robert\AppData\Roaming\Network Monitor II#0_Traffic.ini
2019-02-13 00:48 - 2019-02-13 00:48 - 000000383 _ C:\Users\Robert\AppData\Roaming\Top Process Monitor_Settings.ini
2019-02-13 00:44 - 2019-02-13 00:44 - 000000266 _ C:\Users\Robert\AppData\Roaming\World Population Monitor_Settings.ini
2019-02-13 00:12 - 2019-02-13 00:15 - 000000521 _ C:\Users\Robert\AppData\Roaming\Weather Monitor_Settings.ini
2019-02-13 00:00 - 2019-02-13 00:41 - 000000604 _ C:\Users\Robert\AppData\Roaming\Drives Monitor_Settings.ini
2019-02-12 23:49 - 2019-02-12 23:49 - 000000985 C:\Users\Robert\AppData\Roaming\Network Monitor II#0_Settings.ini
2019-02-12 22:45 - 2019-02-12 22:45 - 000003074 _ C:\Users\Robert\AppData\Roaming\SAS7_000.DAT
2019-02-12 05:04 - 2019-02-12 05:04 - 000004562 _ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2019-02-11 18:26 - 2019-02-11 18:26 - 000016612 _ C:\Users\Robert\Desktop\ListChkdskResult.txt
2019-02-11 18:24 - 2019-02-11 18:24 - 000016612 _ C:\Users\Robert\Desktop\ListChkdskResult1.txt
2019-02-11 17:27 - 2019-02-11 17:28 - 000197679 _ C:\Users\Robert\Desktop\ListChkdskResult.exe
2019-02-11 09:29 - 2019-02-11 09:35 - 011942934 _ C:\WINDOWS\system32\Drivers\etc\HOSTS.bak
2019-02-11 09:12 - 2019-02-11 09:12 - 000003825 _ C:\WINDOWS\system32\Drivers\etc\hosts.txt
2019-02-11 08:45 - 2019-02-11 08:45 - 000001687 _ C:\Users\Robert\Desktop\Hosts File Editor+ v.1.5.7.exe.lnk
2019-02-11 07:54 - 2019-02-11 07:57 - 000008628 ____H C:\Users\Robert\Desktop\DELAYER.GID
2019-02-11 07:54 - 2019-02-11 07:54 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Help
2019-02-11 07:52 - 2008-04-14 03:00 - 000283648 _ (Microsoft Corporation) C:\Users\Robert\Desktop\winhlp32.exe
2019-02-11 00:02 - 2001-09-27 16:43 - 000049152 _ (Cottonwood Software) C:\Delayer.exe
2019-02-11 00:02 - 1997-04-03 20:55 - 000016908 _ C:\Users\Robert\Desktop\DELAYER.HLP
2019-02-11 00:01 - 2019-02-11 00:01 - 000000000 ____D C:\Program Files (x86)\delayer11
2019-02-10 16:17 - 2019-02-10 16:17 - 000000840 __RSH C:\ProgramData\ntuser.pol
2019-02-08 17:12 - 2019-02-08 17:12 - 000001444 _ C:\Users\Public\Desktop\Spybot Anti-Beacon.lnk
2019-02-08 17:12 - 2019-02-08 17:12 - 000000000 ____D C:\WINDOWS\SysWOW64\PolicyDefinitions
2019-02-08 17:12 - 2019-02-08 17:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot Anti-Beacon
2019-02-08 16:37 - 2019-02-08 17:12 - 000000000 ____D C:\Program Files (x86)\Safer-Networking Ltd
2019-02-08 16:37 - 2019-02-08 16:37 - 000000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2019-02-08 09:29 - 2019-02-10 22:32 - 000000117 _ C:\Users\Robert\AppData\Roaming\System Monitor II_UptimeRecord.ini
2019-02-08 06:28 - 2019-02-08 22:32 - 000003978 _ C:\Users\Robert\AppData\Roaming\System Monitor II_CPU0_Settings.ini
2019-02-07 10:14 - 2019-02-07 10:14 - 000001227 _ C:\Users\Public\Desktop\AOMEI Partition Assistant Professional Edition 8.0.lnk
2019-02-07 10:14 - 2019-02-07 10:14 - 000001024 ____H C:\AMTAG.BIN
2019-02-07 10:13 - 2019-02-08 16:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Partition Assistant
2019-02-07 10:13 - 2019-02-07 10:17 - 000000000 ____D C:\Program Files (x86)\AOMEI Partition Assistant
2019-02-07 10:13 - 2019-01-25 20:48 - 002165096 _ C:\WINDOWS\ampa.exe
2019-02-07 10:13 - 2016-12-27 18:45 - 000035760 _ C:\WINDOWS\system32\ddmdrv.sys
2019-02-07 10:13 - 2016-12-27 18:45 - 000033200 _ C:\WINDOWS\SysWOW64\ddmdrv.sys
2019-02-07 10:13 - 2016-12-27 14:15 - 000038320 _ C:\WINDOWS\SysWOW64\ampa.sys
2019-02-07 10:13 - 2016-12-27 14:15 - 000038320 _ C:\WINDOWS\system32\ampa.sys
2019-02-07 10:13 - 2016-09-29 09:44 - 001298584 _ C:\WINDOWS\ddmmain.exe
2019-02-06 17:37 - 2019-02-06 17:38 - 000000128 _ C:\Users\Robert\AppData\Roaming\Earthquakes Meter_Settings.ini
2019-02-06 17:24 - 2019-02-12 22:44 - 000000593 _ C:\Users\Robert\IP_Log_Data.js
2019-02-06 17:19 - 2019-02-07 20:33 - 000000634 _ C:\Users\Robert\AppData\Roaming\All CPU MeterV3_Settings.ini
2019-02-06 17:12 - 2019-02-06 17:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\8GadgetPack
2019-02-06 17:09 - 2019-02-06 17:09 - 000003254 _ C:\WINDOWS\System32\Tasks\SidebarExecute
2019-02-06 17:08 - 2019-02-08 16:51 - 000000000 ____D C:\Program Files\Rainmeter
2019-02-06 15:32 - 2019-02-06 15:32 - 000093960 ____H (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCMON24.SYS
2019-02-06 14:24 - 2019-02-06 14:24 - 000003392 _ C:\WINDOWS\System32\Tasks\EVGAPrecisionX
2019-02-06 13:39 - 2019-02-06 13:39 - 000000000 ____D C:\Tempzxpsign81d248e10da06351
2019-02-06 13:39 - 2019-02-06 13:39 - 000000000 ____D C:\Tempzxpsign1fd4227f11420fcf
2019-02-05 12:43 - 2019-02-05 12:43 - 000002471 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2019-02-05 12:43 - 2019-02-05 12:43 - 000002118 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2019-02-05 12:23 - 2019-02-05 12:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 64-bit fixes
2019-02-04 12:34 - 2019-02-04 12:34 - 000000139 _ C:\Users\Robert\Desktop\SFCFix.zip
2019-02-04 12:33 - 2019-02-04 12:33 - 002347008 _ (niemiro) C:\Users\Robert\Desktop\SFCFix.exe
2019-02-02 12:19 - 2019-02-02 12:19 - 000774560 _ C:\WINDOWS\system32\FNTCACHE.DAT
2019-02-01 10:39 - 2019-02-01 10:59 - 000000000 ____D C:\Program Files (x86)\Audials 2019
2019-02-01 10:39 - 2019-02-01 10:57 - 000000000 ____D C:\ProgramData\RapidSolution
2019-02-01 09:55 - 2019-02-08 09:56 - 000000000 ____D C:\WINDOWS\System32\Tasks\Abelssoft
2019-02-01 09:55 - 2019-02-01 09:55 - 000001980 _ C:\Users\Public\Desktop\SSDFresh.lnk
2019-02-01 09:55 - 2019-02-01 09:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SSDFresh
2019-02-01 09:55 - 2019-02-01 09:55 - 000000000 ____D C:\ProgramData\Abelssoft
2019-02-01 09:55 - 2019-02-01 09:55 - 000000000 ____D C:\Program Files (x86)\SSDFresh
2019-01-31 20:17 - 2019-01-31 20:17 - 000001160 _ C:\Users\Robert\Desktop\Hard Disk Sentinel.lnk
2019-01-31 20:17 - 2019-01-31 20:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hard Disk Sentinel
2019-01-31 11:41 - 2019-01-31 11:41 - 072520776 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoRes64.dat
2019-01-31 11:41 - 2019-01-31 11:41 - 023073815 _ C:\WINDOWS\system32\Drivers\RTAIODAT.DAT
2019-01-31 11:41 - 2019-01-31 11:41 - 007178544 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EEP64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 007101824 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 006270264 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPP64AF3.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 005347072 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv211.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003677224 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTSnMg64.cpl
2019-01-31 11:41 - 2019-01-31 11:41 - 003418072 _ (DTS, Inc.) C:\WINDOWS\system32\slcnt64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003319480 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkApi64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003306896 _ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE2.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003281232 _ (Realtek Semiconductor Corp.) C:\WINDOWS\SysWOW64\RltkAPO.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003159472 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtPgEx64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 003128888 _ (DTS, Inc.) C:\WINDOWS\system32\sltech64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 002930216 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RCoInstII64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 002444760 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOv201.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 002198048 _ (Yamaha Corporation) C:\WINDOWS\system32\YamahaAE.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001971448 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001965232 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPD64AF3.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001788032 _ (DTS) C:\WINDOWS\system32\DTSS2SpeakerDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001598472 _ (DTS) C:\WINDOWS\system32\DTSS2HeadphoneDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001544328 _ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOProp.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001516368 _ (DTS) C:\WINDOWS\system32\DTSBoostDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001448856 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOv251gm.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001435216 _ (Synopsys, Inc.) C:\WINDOWS\system32\SRRPTR64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001396232 _ (Sound Research, Corp.) C:\WINDOWS\system32\SECOMN64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001382312 _ (TOSHIBA Corporation) C:\WINDOWS\system32\tosade.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001372472 _ (Dolby Laboratories) C:\WINDOWS\system32\DAX3APOv251.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001353384 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RTCOM64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001337720 _ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaeapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001318912 _ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDHF64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001282616 _ (Sound Research, Corp.) C:\WINDOWS\system32\SEAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001259808 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOvlldp.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001180584 _ (Sound Research, Corp.) C:\WINDOWS\system32\SEHDRA64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001164696 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyAPOvlldpgm.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001159264 _ (Dolby Laboratories) C:\WINDOWS\system32\DolbyDAX2APOProp.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001073736 _ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SECOMN32.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 001027888 _ (Sound Research, Corp.) C:\WINDOWS\SysWOW64\SEHDHF32.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000994744 _ (DTS, Inc.) C:\WINDOWS\system32\sl3apo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000965088 _ (Sony Corporation) C:\WINDOWS\system32\SFSS_APO.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000888616 _ (ICEpower a/s) C:\WINDOWS\system32\ICEsoundAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000873544 _ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo264.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000852208 _ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tosasfapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000807808 _ (ICEpower) C:\WINDOWS\system32\ICEsoundService64.exe
2019-01-31 11:41 - 2019-01-31 11:41 - 000751376 _ (DTS) C:\WINDOWS\system32\DTSBassEnhancementDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000734848 _ (DTS) C:\WINDOWS\system32\DTSSymmetryDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000715720 _ (DTS) C:\WINDOWS\system32\DTSVoiceClarityDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000692224 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtDataProc64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000604872 _ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\tossaemaxapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000541192 _ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSX64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000511720 _ (DTS) C:\WINDOWS\system32\DTSNeoPCDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000467232 _ (Synopsys, Inc.) C:\WINDOWS\system32\SRAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000453352 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EED64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000452816 _ (DTS) C:\WINDOWS\system32\DTSLimiterDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000448680 _ (DTS) C:\WINDOWS\system32\DTSGainCompensatorDLL64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000447256 _ (Toshiba Client Solutions Co., Ltd.) C:\WINDOWS\system32\toseaeapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000416584 _ (Harman) C:\WINDOWS\system32\HMUI.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000406528 _ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2APIPCLL.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000392936 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEP64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000381488 _ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000378456 _ (Dolby Laboratories) C:\WINDOWS\system32\HiFiDAX2API.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000367688 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64AF3.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000366200 _ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\HMAPO.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000360424 _ (Harman) C:\WINDOWS\system32\HMClariFi.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000343768 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtlCPAPI64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000341224 _ (Synopsys, Inc.) C:\WINDOWS\SysWOW64\SRCOM.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000341224 _ (Synopsys, Inc.) C:\WINDOWS\system32\SRCOM.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000333088 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPO64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000327336 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DHT64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000327328 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RP3DAA64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000316080 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64F3.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000278352 _ (Dolby Laboratories) C:\WINDOWS\system32\DDPA64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000266616 _ (TODO: <Company name>) C:\WINDOWS\system32\slprp64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000261312 _ (DTS) C:\WINDOWS\system32\DTSGFXAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000261280 _ (DTS) C:\WINDOWS\system32\DTSLFXAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000260288 _ (DTS) C:\WINDOWS\system32\DTSGFXAPONS64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000231976 _ (Synopsys, Inc.) C:\WINDOWS\system32\SFNHK64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000230784 _ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSTSH64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000220448 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEED64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000218352 _ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSHP64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000203912 _ (Harman) C:\WINDOWS\system32\HMHVS.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000195763 _ C:\WINDOWS\system32\ICEsoundService.bin
2019-01-31 11:41 - 2019-01-31 11:41 - 000191008 _ (Harman) C:\WINDOWS\system32\HMEQ_Voice.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000191008 _ (Harman) C:\WINDOWS\system32\HMEQ.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000179672 _ (Harman) C:\WINDOWS\system32\HMLimiter.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000175824 _ (ASUSTeK COMPUTER INC.) C:\WINDOWS\system32\ATKWMI.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000175016 _ (SRS Labs, Inc.) C:\WINDOWS\system32\SRSWOW64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000158776 _ (TOSHIBA Corporation) C:\WINDOWS\system32\tadefxapo.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000157408 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EEL64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000154440 _ (Harman) C:\WINDOWS\system32\HarmanAudioInterface.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000139832 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EEA64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000122424 _ (Real Sound Lab SIA) C:\WINDOWS\system32\CONEQMSAPOGUILibrary.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000118664 _ C:\WINDOWS\system32\AcpiServiceVnA64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000116600 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEL64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000105384 _ C:\WINDOWS\system32\audioLibVc.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000093968 _ (Dolby Laboratories, Inc.) C:\WINDOWS\system32\RTEEG64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000090976 _ (Synopsys, Inc.) C:\WINDOWS\system32\SFCOM64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000090232 _ (Dolby Laboratories) C:\WINDOWS\system32\R4EEG64A.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000088384 _ (Synopsys, Inc.) C:\WINDOWS\system32\SFAPO64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000083688 _ (Virage Logic Corporation / Sonic Focus) C:\WINDOWS\SysWOW64\SFCOM.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000075616 _ (TOSHIBA CORPORATION.) C:\WINDOWS\system32\tepeqapo64.dll
2019-01-31 11:41 - 2019-01-31 11:41 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2019-01-31 11:40 - 2019-01-31 11:40 - 001139848 _ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2019-01-31 11:19 - 2019-01-31 11:19 - 001083424 _ C:\WINDOWS\system32\AmRdrIco.icl
2019-01-31 11:17 - 2019-01-31 11:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Driver Booster PRO
2019-01-31 11:16 - 2019-01-31 11:16 - 000000000 ____D C:\2-click run
2019-01-31 10:45 - 2019-01-31 10:45 - 025117952 _ (StarWind Software ) C:\Users\Robert\Desktop\starwindconverterV9.110.exe
2019-01-30 23:31 - 2019-01-30 23:31 - 363172271 _ C:\Users\Robert\Desktop\An FBI Negotiator’s Secret to Winning Any Exchange _ Inc.mp4
2019-01-30 18:22 - 2019-01-30 18:22 - 008406934 _ C:\Users\Robert\Desktop\COMPONENTS.zip
2019-01-30 18:13 - 2019-02-06 13:15 - 000000000 ____D C:\Users\Robert\AppData\Roaming\epm
2019-01-30 13:22 - 2019-01-30 13:22 - 000001411 _ C:\Users\Public\Desktop\EaseUS Partition Master 13.0.lnk
2019-01-30 13:22 - 2019-01-30 13:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Partition Master 13.0
2019-01-30 13:22 - 2018-11-27 12:08 - 005247120 _ C:\WINDOWS\system32\BootMan.exe
2019-01-30 13:22 - 2018-11-27 12:08 - 003551376 _ C:\WINDOWS\SysWOW64\BootMan.exe
2019-01-30 13:22 - 2018-11-27 12:08 - 000022160 _ C:\WINDOWS\SysWOW64\EuEpmGdi.dll
2019-01-30 13:22 - 2018-11-27 12:08 - 000018576 _ C:\WINDOWS\system32\EuEpmGdi.dll
2019-01-30 13:22 - 2018-10-24 13:53 - 000010848 _ C:\WINDOWS\system32\EuGdiDrv.sys
2019-01-30 13:22 - 2018-10-18 13:05 - 000132240 _ C:\WINDOWS\system32\setupempdrvx64.exe
2019-01-30 13:22 - 2018-10-18 04:35 - 000034496 _ C:\WINDOWS\system32\epmntdrv.sys
2019-01-30 13:22 - 2018-10-18 01:38 - 000030416 _ (Windows (R) Codename Longhorn DDK provider) C:\WINDOWS\system32\EPMVolFlt.sys
2019-01-30 13:22 - 2018-10-18 01:38 - 000030416 _ (Windows (R) Codename Longhorn DDK provider) C:\WINDOWS\system32\Drivers\EPMVolFlt.sys
2019-01-29 22:05 - 2019-01-29 22:49 - 000000894 _ C:\Users\Robert\Desktop\Chris Star Trek reference notes.txt
2019-01-29 12:15 - 2019-01-29 12:15 - 000000979 _ C:\Users\Robert\Desktop\Sweet Home 3D.lnk
2019-01-29 12:15 - 2019-01-29 12:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eTeks Sweet Home 3D
2019-01-26 18:36 - 2019-02-13 12:41 - 000000000 ____D C:\FRST
2019-01-25 13:49 - 2019-01-25 13:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\smartmontools
2019-01-25 13:49 - 2019-01-25 13:49 - 000000000 ____D C:\Program Files\smartmontools
2019-01-25 13:41 - 2019-01-25 13:41 - 001265846 _ (www.smartmontools.org) C:\Users\Robert\Desktop\smartmontools-7.0-1.win32-setup.exe
2019-01-25 13:01 - 2019-02-07 09:39 - 000000000 ____D C:\Users\Robert\AppData\Roaming\gsmartcontrol
2019-01-25 13:00 - 2019-02-07 09:39 - 000000000 ____D C:\Users\Robert\Desktop\gsmartcontrol-1.1.3-win32
2019-01-25 12:59 - 2019-01-25 12:59 - 010745236 _ C:\Users\Robert\Desktop\gsmartcontrol-1.1.3-win32.zip
2019-01-24 19:54 - 2019-01-24 19:54 - 000002465 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002455 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002454 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002418 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002417 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002411 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002405 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000002397 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2019-01-24 19:54 - 2019-01-24 19:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools
2019-01-24 19:54 - 2019-01-24 19:54 - 000000000 ____D C:\Program Files\Common Files\DESIGNER
2019-01-24 19:51 - 2019-01-24 19:51 - 000000000 ____D C:\Program Files\Microsoft Office 15
2019-01-24 19:18 - 2019-01-24 19:18 - 000003340 _ C:\WINDOWS\System32\Tasks\Office 2019 Statique Activation Planificateur
2019-01-24 18:48 - 2019-01-24 18:48 - 000003356 _ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2536635842-542287166-2959069790-1002
2019-01-24 18:48 - 2019-01-24 18:48 - 000002404 _ C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-01-24 18:21 - 2019-01-24 19:54 - 000000000 ____D C:\Program Files\Microsoft Office
2019-01-18 11:33 - 2019-01-18 11:34 - 000141924 ____R C:\Users\Robert\Desktop\Markup and Margin Sheet.pdf
2019-01-18 01:22 - 2019-02-04 12:35 - 000000000 ____D C:\SFCFix
2019-01-17 15:17 - 2019-02-09 22:32 - 000000000 ____D C:\Users\Robert\Desktop\Hiren's BootCD WinPE10 Premium Edition Build 181211 (Dec. 11, 2018) [CracksNow]
2019-01-17 09:45 - 2019-01-17 09:45 - 000002142 _ C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2019-01-17 09:45 - 2019-01-17 09:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2019-01-17 01:34 - 2019-01-17 01:34 - 000000887 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr. Folder.lnk
2019-01-16 18:07 - 2019-01-16 18:07 - 000002095 _ C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
2019-01-16 17:11 - 2019-02-12 22:43 - 141557760 _ C:\WINDOWS\system32\config\SOFTWARE
2019-01-16 17:11 - 2019-02-12 22:43 - 026738688 _ C:\WINDOWS\system32\config\SYSTEM
2019-01-16 17:11 - 2019-02-12 22:43 - 001048576 _ C:\WINDOWS\system32\config\DEFAULT
2019-01-16 17:11 - 2019-02-12 22:43 - 000077824 _ C:\WINDOWS\system32\config\SAM
2019-01-16 17:11 - 2019-02-12 22:43 - 000073728 _ C:\WINDOWS\system32\config\SECURITY
2019-01-15 13:52 - 2019-01-15 13:52 - 000002055 _ C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\NordVPN.lnk
2019-01-15 13:40 - 2019-01-15 13:40 - 000000958 _ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2019-01-15 13:40 - 2019-01-15 13:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2019-01-15 13:40 - 2016-12-21 14:52 - 000040240 _ (VS Revo Group) C:\WINDOWS\system32\Drivers\revoflt.sys
2019-01-15 12:51 - 2019-01-11 01:31 - 000133328 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2019-01-15 12:51 - 2019-01-11 01:22 - 000125320 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000978336 _ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000978336 _ C:\WINDOWS\system32\vulkan-1.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000845216 _ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000845216 _ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000552536 _ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000456848 _ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-01-15 12:49 - 2019-01-11 20:05 - 000268192 _ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2019-01-15 12:49 - 2019-01-11 20:05 - 000268192 _ C:\WINDOWS\system32\vulkaninfo.exe
2019-01-15 12:49 - 2019-01-11 20:05 - 000243616 _ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2019-01-15 12:49 - 2019-01-11 20:05 - 000243616 _ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-01-15 12:49 - 2019-01-11 20:04 - 004946232 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 004316304 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 002018392 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6441771.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 002003600 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 001512352 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 001467864 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6441771.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 001461152 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 001126544 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 000750520 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 000631896 _ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 000609368 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2019-01-15 12:49 - 2019-01-11 20:04 - 000521688 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-01-15 12:49 - 2019-01-11 20:03 - 040262912 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-01-15 12:49 - 2019-01-11 20:03 - 035158736 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-01-15 12:49 - 2019-01-11 16:03 - 015911384 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 013205768 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001471424 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001462024 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001167584 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001151984 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 001145536 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 000914400 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 000822392 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 000794448 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-01-15 12:49 - 2019-01-11 16:02 - 000637664 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-01-15 12:49 - 2019-01-11 16:01 - 019717352 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-01-15 12:49 - 2019-01-11 16:01 - 016993240 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-01-15 12:49 - 2019-01-11 16:01 - 005003032 _ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2019-01-15 12:49 - 2019-01-11 16:01 - 004260704 _ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2019-01-15 12:49 - 2019-01-11 03:06 - 000048472 _ C:\WINDOWS\system32\nvinfo.pb
2019-01-15 11:14 - 2019-02-12 22:43 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2019-01-15 11:14 - 2019-01-22 09:03 - 000001046 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 14.lnk
2019-01-15 11:14 - 2019-01-22 09:03 - 000001034 _ C:\Users\Public\Desktop\TeamViewer 14.lnk
2019-01-15 10:38 - 2019-01-15 10:38 - 000000037 _ C:\Users\Robert\Desktop\SBDC Webinar.txt
2019-01-15 09:58 - 2019-01-15 13:32 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Zoom
2019-01-14 14:23 - 2019-01-14 14:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon
2019-01-14 14:16 - 2019-01-14 14:16 - 000001919 _ C:\ProgramData\Microsoft\Windows\Start Menu\Software Updates.lnk
2019-01-14 10:56 - 2019-01-14 10:56 - 000000043 _ C:\WINDOWS\gswin32.ini
==================== One month (modified) ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2019-02-13 12:42 - 2019-01-03 02:13 - 000000000 ____D C:\Temp
2019-02-13 12:28 - 2018-10-04 03:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-02-13 09:23 - 2018-11-03 07:15 - 000000000 ____D C:\Program Files\Waterfox
2019-02-13 03:00 - 2018-10-04 02:39 - 000000000 ____D C:\WINDOWS\system32\msmq
2019-02-13 00:43 - 2017-01-11 22:55 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Everything
2019-02-13 00:35 - 2017-12-28 08:02 - 000000339 _ C:\Users\Robert\AppData\Roaming\Drives Meter_Settings.ini
2019-02-12 23:49 - 2017-12-28 15:56 - 000000025 _ C:\Users\Robert\AppData\Roaming\Network Meter_Usage.ini
2019-02-12 23:00 - 2017-12-28 11:00 - 000010427 _ C:\Users\Robert\Network_Meter_Data.js
2019-02-12 22:49 - 2018-10-04 03:44 - 000946072 _ C:\WINDOWS\system32\PerfStringBackup.INI
2019-02-12 22:49 - 2018-09-14 23:31 - 000000000 ____D C:\WINDOWS\INF
2019-02-12 22:44 - 2018-10-07 22:39 - 000000000 ____D C:\ProgramData\ProductData
2019-02-12 22:44 - 2018-09-14 23:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-02-12 22:44 - 2017-08-03 15:50 - 000000000 ____D C:\Program Files (x86)\Chameleon Clock
2019-02-12 22:43 - 2018-10-04 03:40 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-02-12 22:43 - 2018-10-02 12:14 - 000000000 ____D C:\ProgramData\NVIDIA
2019-02-12 22:43 - 2018-09-14 22:09 - 000524288 _ C:\WINDOWS\system32\config\BBI
2019-02-12 22:43 - 2017-01-12 08:00 - 000000000 ____D C:\ProgramData\VMware
2019-02-12 20:49 - 2017-01-19 15:33 - 000000000 ____D C:\Users\Robert\AppData\Roaming\qBittorrent
2019-02-12 18:05 - 2019-01-03 11:02 - 000004146 _ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{8E893A56-B045-48A2-8817-29DB664228F5}
2019-02-11 17:07 - 2017-01-12 22:15 - 000000000 ____D C:\ProgramData\Temp
2019-02-11 12:54 - 2016-07-16 03:47 - 000000180 _ C:\WINDOWS\win.ini
2019-02-11 09:47 - 2017-01-20 08:36 - 000000000 ____D C:\Program Files\Mozilla Firefox
2019-02-11 09:25 - 2018-04-17 18:53 - 000000000 ____D C:\Program Files (x86)\Host File Editor
2019-02-11 08:01 - 2017-01-12 19:38 - 000000000 ____D C:\Users\Robert\AppData\Roaming\VMware
2019-02-11 07:54 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\system32\Macromed
2019-02-10 23:26 - 2018-10-04 02:41 - 000000000 ____D C:\Users\Robert
2019-02-10 19:39 - 2018-09-08 12:39 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Photolemur
2019-02-10 17:59 - 2018-11-18 22:52 - 000000000 ____D C:\Users\Robert\AppData\Roaming\MPC-HC
2019-02-10 14:53 - 2017-01-19 12:16 - 000000000 ____D C:\Users\Robert\AppData\Roaming\XnView
2019-02-10 11:53 - 2018-11-16 06:51 - 000526346 _ C:\WINDOWS\system32\Drivers\etc\hosts.020919
2019-02-10 11:22 - 2018-11-17 21:14 - 000001474 _ C:\Users\Robert\Desktop\WaterFox settings mod.txt
2019-02-09 16:02 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2019-02-09 14:35 - 2018-06-16 09:14 - 000000000 ____D C:\ProgramData\ThumbsPlus
2019-02-09 14:35 - 2017-01-13 10:42 - 000000000 ____D C:\Users\Robert\AppData\Roaming\ThumbsPlus
2019-02-08 16:46 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-02-07 16:55 - 2017-01-12 22:52 - 000000000 ____D C:\Program Files (x86)\Backblaze
2019-02-07 16:21 - 2018-02-14 08:02 - 000002305 _ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-02-07 10:02 - 2017-12-28 20:44 - 000001050 _ C:\Users\Robert\AppData\Roaming\Network Meter_Settings.ini
2019-02-07 02:17 - 2018-09-22 00:27 - 000000000 ____D C:\Program Files (x86)\Intel Driver and Support Assistant
2019-02-06 21:14 - 2018-10-26 17:43 - 000000000 ____D C:\Users\Robert\Desktop\comp
2019-02-06 17:13 - 2018-09-14 23:33 - 000000000 ___SD C:\Program Files\Windows Sidebar
2019-02-06 17:13 - 2018-09-14 23:33 - 000000000 ___SD C:\Program Files (x86)\Windows Sidebar
2019-02-06 13:56 - 2017-01-11 17:42 - 000000000 ____D C:\Users\Robert\AppData\LocalLow\Mozilla
2019-02-06 13:53 - 2018-10-19 19:56 - 000017878 _ C:\Users\Robert\Desktop\Markup calculator.xlsx
2019-02-06 13:53 - 2018-07-03 10:03 - 000000000 ____D C:\Users\Robert\AppData\Roaming\XnViewMP
2019-02-06 12:48 - 2019-01-03 13:24 - 000002532 _ C:\WINDOWS\System32\Tasks\SamsungMagician
2019-02-06 12:36 - 2018-07-01 14:10 - 000002548 ____H C:\WINDOWS\EPMBatch.ept
2019-02-05 22:32 - 2017-01-18 22:44 - 000000000 ____D C:\Users\Robert\AppData\Roaming\ObviousIdea
2019-02-05 12:25 - 2017-01-19 09:45 - 000000000 ____D C:\Program Files\CCleaner
2019-02-05 12:25 - 2017-01-14 08:22 - 000000000 ____D C:\Program Files (x86)\Adobe Reader 64-bit fixes
2019-02-05 12:25 - 2017-01-11 17:38 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-02-05 11:06 - 2018-06-03 10:57 - 000000673 _ C:\WINDOWS\clipc.INI
2019-02-04 21:48 - 2017-01-11 21:28 - 000000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2019-02-02 12:02 - 2018-10-06 19:48 - 000000000 ____D C:\Users\Robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\- SYSTEM Test
2019-02-01 11:19 - 2017-01-19 15:48 - 000000000 ____D C:\Program Files\Adobe
2019-01-31 20:17 - 2017-01-17 00:15 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2019-01-31 11:43 - 2018-10-07 22:33 - 000000000 ____D C:\Users\Robert\AppData\LocalLow\IObit
2019-01-31 11:43 - 2018-10-07 22:32 - 000000000 ____D C:\ProgramData\IObit
2019-01-31 11:43 - 2018-10-02 17:32 - 000000000 ____D C:\Users\Robert\AppData\Roaming\IObit
2019-01-31 11:41 - 2018-10-30 22:27 - 006400040 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\Drivers\RTKVHD64.sys
2019-01-31 11:41 - 2018-10-30 22:27 - 003761640 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RltkAPO64.dll
2019-01-31 11:41 - 2018-10-30 22:27 - 000193040 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCfg64.dll
2019-01-31 11:41 - 2018-10-30 22:27 - 000023752 _ (Realtek Semiconductor Corp.) C:\WINDOWS\system32\RtkCoLDR64.dll
2019-01-31 11:41 - 2018-07-21 23:42 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2019-01-31 11:41 - 2018-07-21 23:38 - 000000000 ____D C:\WINDOWS\system32\RTCOM
2019-01-31 11:41 - 2017-04-12 06:16 - 000000000 ____D C:\WINDOWS\system32\DAX2
2019-01-31 11:19 - 2018-01-22 11:45 - 000109504 _ () C:\WINDOWS\system32\Drivers\AmUStor.sys
2019-01-30 18:35 - 2018-08-28 09:05 - 000000000 ____D C:\Users\Robert\AppData\Roaming\ON1
2019-01-30 13:22 - 2018-07-01 14:04 - 000000000 ____D C:\Program Files (x86)\EaseUS Partition Master
2019-01-30 13:22 - 2017-01-28 10:46 - 000000000 ____D C:\Program Files (x86)\EaseUS
2019-01-29 12:15 - 2017-01-11 22:38 - 000000000 ____D C:\Program Files\Sweet Home 3D
2019-01-28 21:17 - 2018-09-14 23:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-01-25 00:32 - 2019-01-04 22:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2019-01-25 00:32 - 2018-10-02 12:13 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-01-25 00:32 - 2018-10-02 12:13 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-01-25 00:32 - 2018-10-02 12:13 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2019-01-24 19:54 - 2018-09-14 23:33 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2019-01-24 18:48 - 2018-07-23 23:10 - 000000000 ___RD C:\Users\Robert\OneDrive
2019-01-24 18:07 - 2018-07-23 23:23 - 000000000 ____D C:\Program Files\Office
2019-01-24 13:37 - 2017-08-24 16:55 - 000042904 _ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2019-01-21 00:49 - 2019-01-13 16:45 - 000004210 _ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-01-17 14:05 - 2018-12-01 11:08 - 000000000 ____D C:\Program Files (x86)\SpeedFan
2019-01-17 13:40 - 2018-11-03 09:29 - 000000000 ____D C:\Windows10Upgrade
2019-01-17 09:45 - 2018-08-18 03:21 - 000000000 ____D C:\Users\Robert\AppData\Roaming\MyPhoneExplorer
2019-01-17 09:45 - 2018-08-18 03:21 - 000000000 ____D C:\Program Files (x86)\MyPhoneExplorer
2019-01-17 01:34 - 2017-01-19 12:29 - 000000000 ____D C:\Program Files\Dr. Folder
2019-01-16 19:43 - 2018-09-14 23:33 - 000000000 ___HD C:\Program Files\WindowsApps.tmp
2019-01-16 19:02 - 2018-09-14 23:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-01-16 19:02 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\registration
2019-01-16 17:42 - 2017-07-08 13:20 - 000000000 ____D C:\Program Files (x86)\XnView
2019-01-16 17:12 - 2018-11-12 22:05 - 132120576 _ C:\WINDOWS\system32\config\software.rcbak
2019-01-16 17:12 - 2018-11-12 22:05 - 026214400 _ C:\WINDOWS\system32\config\system.rcbak
2019-01-16 17:12 - 2018-11-12 22:05 - 000786432 _ C:\WINDOWS\system32\config\default.rcbak
2019-01-16 17:12 - 2018-11-12 22:05 - 000155648 _ C:\WINDOWS\system32\config\sam.rcbak
2019-01-16 17:12 - 2018-11-12 22:05 - 000065536 _ C:\WINDOWS\system32\config\security.rcbak
2019-01-16 14:40 - 2018-02-04 18:56 - 000000000 ____D C:\Program Files (x86)\TinyTask
2019-01-16 14:01 - 2018-09-22 10:49 - 000000000 ____D C:\Program Files (x86)\FotoSketcher
2019-01-15 17:36 - 2018-09-14 22:09 - 006533120 _ C:\WINDOWS\system32\config\drivers.rcbak
2019-01-15 13:55 - 2017-02-05 01:32 - 000000000 ____D C:\Program Files\Revo Uninstaller Pro
2019-01-15 13:52 - 2019-01-12 17:38 - 000001986 _ C:\Users\Public\Desktop\NordVPN.lnk
2019-01-15 01:04 - 2018-09-14 23:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-01-14 22:21 - 2018-08-09 00:16 - 000000000 ____D C:\ProgramData\Packages
2019-01-14 11:17 - 2018-04-11 15:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
==================== Files in the root of some directories =======
2003-08-07 08:34 - 2003-08-07 08:34 - 000000000 _ () C:\ProgramData\sdpsenv.dat
2016-02-04 10:11 - 2016-02-04 10:11 - 000002045 _ () C:\ProgramData\whlb32g.dll
2019-02-06 17:24 - 2019-02-12 22:44 - 000000593 _ () C:\Users\Robert\IP_Log_Data.js
2017-12-28 11:00 - 2019-02-12 23:00 - 000010427 _ () C:\Users\Robert\Network_Meter_Data.js
2017-01-31 11:57 - 2003-10-30 11:00 - 000353280 _ (Stardust Software) C:\Program Files (x86)\SCMain.exe
2019-02-06 17:19 - 2019-02-07 20:33 - 000000634 _ () C:\Users\Robert\AppData\Roaming\All CPU MeterV3_Settings.ini
2017-12-28 10:10 - 2018-01-07 01:48 - 000000412 _ () C:\Users\Robert\AppData\Roaming\All CPU Meter_Settings.ini
2017-12-28 08:02 - 2019-02-13 00:35 - 000000339 _ () C:\Users\Robert\AppData\Roaming\Drives Meter_Settings.ini
2019-02-13 00:00 - 2019-02-13 00:41 - 000000604 _ () C:\Users\Robert\AppData\Roaming\Drives Monitor_Settings.ini
2019-02-06 17:37 - 2019-02-06 17:38 - 000000128 _ () C:\Users\Robert\AppData\Roaming\Earthquakes Meter_Settings.ini
2018-10-18 09:51 - 2018-10-18 09:51 - 000000312 _ () C:\Users\Robert\AppData\Roaming\license
2017-12-28 20:44 - 2019-02-07 10:02 - 000001050 _ () C:\Users\Robert\AppData\Roaming\Network Meter_Settings.ini
2017-12-28 15:56 - 2019-02-12 23:49 - 000000025 _ () C:\Users\Robert\AppData\Roaming\Network Meter_Usage.ini
2019-02-12 23:49 - 2019-02-12 23:49 - 000000985 () C:\Users\Robert\AppData\Roaming\Network Monitor II#0_Settings.ini
2019-02-13 02:59 - 2019-02-13 11:59 - 000000130 () C:\Users\Robert\AppData\Roaming\Network Monitor II#0_Traffic.ini
2018-10-02 12:36 - 2018-10-16 21:56 - 000000270 _ () C:\Users\Robert\AppData\Roaming\pppe_log.txt
2019-02-12 22:45 - 2019-02-12 22:45 - 000003074 _ () C:\Users\Robert\AppData\Roaming\SAS7_000.DAT
2017-11-05 08:53 - 2017-11-08 09:03 - 000601088 _ () C:\Users\Robert\AppData\Roaming\SharedSettings.ccs
2019-02-08 06:28 - 2019-02-08 22:32 - 000003978 _ () C:\Users\Robert\AppData\Roaming\System Monitor II_CPU0_Settings.ini
2019-02-08 09:29 - 2019-02-10 22:32 - 000000117 _ () C:\Users\Robert\AppData\Roaming\System Monitor II_UptimeRecord.ini
2019-02-13 00:48 - 2019-02-13 00:48 - 000000383 _ () C:\Users\Robert\AppData\Roaming\Top Process Monitor_Settings.ini
2019-02-13 00:12 - 2019-02-13 00:15 - 000000521 _ () C:\Users\Robert\AppData\Roaming\Weather Monitor_Settings.ini
2019-02-13 00:44 - 2019-02-13 00:44 - 000000266 _ () C:\Users\Robert\AppData\Roaming\World Population Monitor_Settings.ini
2019-01-03 02:13 - 2019-01-03 02:13 - 000000000 _ () C:\Users\Robert\AppData\Local\oobelibMkey.log
2018-07-06 08:44 - 2018-08-02 12:57 - 000002963 _ () C:\Users\Robert\AppData\Local\Perfmon.PerfmonCfg
2019-01-25 13:45 - 2019-01-25 13:45 - 000000218 _ () C:\Users\Robert\AppData\Local\recently-used.xbel
2017-01-11 18:07 - 2019-01-14 17:06 - 000007658 _ () C:\Users\Robert\AppData\Local\Resmon.ResmonCfg
2018-06-09 15:02 - 2019-02-13 12:32 - 610763776 _ () C:\Users\Robert\AppData\Local\SageThumbs.db3
2019-01-12 10:49 - 2019-01-12 10:49 - 016040448 _ () C:\Users\Robert\AppData\Local\Sync-1547318938.msi
2019-01-12 10:49 - 2019-01-12 10:49 - 000192518 _ () C:\Users\Robert\AppData\Local\Sync-1547318938.msi.log
2017-09-29 19:09 - 2017-09-29 19:09 - 000000000 _ () C:\Users\Robert\AppData\Local\{890F3F8A-F9BD-4993-A048-4AB71E9986FF}
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
Last edited: