Jump to content

ProblemsRBad

Members
  • Content count

    1,123
  • Joined

  • Last visited

  • Days Won

    1

About ProblemsRBad

  • Rank
    $ Supporting Member

Profile Information

  • Gender
    Not Telling
  • OS
    Windows 10

Profile Fields

  • Country
  1. Thanks a lot Broni, updated them and windows, now everything is working great.
  2. Ok I managed to fix the keyboard issue. Just had the Num Lock on, turning it off fixed the problem. Sophos scan was clean so I did not get a log. Here is other logs Results of screen317's Security Check version 1.014 --- 12/23/15 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! ESET NOD32 Antivirus 7.0 Malwarebytes Antivirus out of date! `````````Anti-malware/Other Utilities Check:````````` Java 8 Update 91 Java version 32-bit out of Date! Adobe Flash Player 21.0.0.242 Adobe Reader XI Google Chrome (63.0.3239.132) Google Chrome (SetupMetrics...) Google Chrome (SetupMetrics.pma..) ````````Process Check: objlist.exe by Laurent```````` ESET NOD32 Antivirus egui.exe ESET NOD32 Antivirus ekrn.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamtray.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: 1% ````````````````````End of Log`````````````````````` ------------------------------------------------------------------------------------------ Farbar Service Scanner Version: 27-01-2016 Ran by User (administrator) on 20-01-2018 at 11:12:12 Running from "D:\Users\User\Desktop" Microsoft Windows 7 Professional Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => File is digitally signed C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed C:\Windows\System32\dhcpcore.dll => File is digitally signed C:\Windows\System32\drivers\afd.sys => File is digitally signed C:\Windows\System32\drivers\tdx.sys => File is digitally signed C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed C:\Windows\System32\dnsrslvr.dll => File is digitally signed C:\Windows\System32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\System32\mpssvc.dll => File is digitally signed C:\Windows\System32\bfe.dll => File is digitally signed C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed C:\Windows\System32\SDRSVC.dll => File is digitally signed C:\Windows\System32\vssvc.exe => File is digitally signed C:\Windows\System32\wscsvc.dll => File is digitally signed C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed C:\Windows\System32\wuaueng.dll => File is digitally signed C:\Windows\System32\qmgr.dll => File is digitally signed C:\Windows\System32\es.dll => File is digitally signed C:\Windows\System32\cryptsvc.dll => File is digitally signed C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed C:\Windows\System32\ipnathlp.dll => File is digitally signed C:\Windows\System32\iphlpsvc.dll => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed **** End of log ****
  3. Before we started , they said the keyboard was working normal. Now some of the keys type not what they are supposed to. I have tried updating the keyboard driver, Windows said it's up to date. I have check make sure the keyboard is set to us, it is. Not sure how to fix the keys back to normal. Can you help with this please?
  4. Thank you Broni here is fix log: Fix result of Farbar Recovery Scan Tool (x64) Version: 17.01.2018 01 Ran by User (20-01-2018 10:06:09) Run:1 Running from D:\Users\User\Desktop Loaded Profiles: User (Available Profiles: User) Boot Mode: Normal ============================================== fixlist content: ***************** S2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" S3 catchme; \??\C:\ComboFix\catchme.sys [X] 2016-11-03 11:01 - 2016-11-03 11:01 - 007065600 _____ () C:\Program Files (x86)\GUTD8E2.tmp 2016-05-21 18:00 - 2016-05-21 18:00 - 000000021 _____ () C:\Users\User\AppData\Roaming\fixcfg.ini ***************** "HKLM\System\CurrentControlSet\Services\RichVideo" => removed successfully RichVideo => service removed successfully catchme => service not found. C:\Program Files (x86)\GUTD8E2.tmp => moved successfully C:\Users\User\AppData\Roaming\fixcfg.ini => moved successfully ==== End of Fixlog 10:06:09 ====
  5. Thanks the scan finish here is the logs: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.01.2018 01 Ran by User (administrator) on USER-PC (19-01-2018 12:40:50) Running from D:\Users\User\Desktop Loaded Profiles: User (Available Profiles: User) Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Camshare Inc.) C:\Program Files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (SplitCam Co.) C:\Program Files (x86)\SplitCam\SplitCamService.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Camshare, Inc.) C:\Program Files (x86)\Camfrog\Camfrog Video Chat\Camfrog Video Chat.exe () C:\Program Files (x86)\Camfrog\Camfrog Video Chat\camfrog_cef.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5549768 2014-09-30] (ESET) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10151968 2010-04-20] (Realtek Semiconductor) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-03-22] (Apple Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation) HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2018-01-18] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2016-05-21] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{A229B62A-8C6E-4588-8B12-BED435B7CF9C}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{B841D1F0-52EC-4F8E-AF11-60C6ABF3D201}: [DhcpNameServer] 219.76.98.66 218.102.52.81 Internet Explorer: ================== HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-859187355-2626154896-303692081-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-859187355-2626154896-303692081-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.yahoo.com/ SearchScopes: HKU\S-1-5-21-859187355-2626154896-303692081-1000 -> DefaultScope {0EE7F8EA-A3E0-45E8-9301-FA23CBAE085E} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKU\S-1-5-21-859187355-2626154896-303692081-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-859187355-2626154896-303692081-1000 -> {0EE7F8EA-A3E0-45E8-9301-FA23CBAE085E} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-05-20] (Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-20] (Oracle Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-20] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-20] (Oracle Corporation) FireFox: ======== FF DefaultProfile: uklrygk3.default FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uklrygk3.default [2018-01-19] FF Homepage: Mozilla\Firefox\Profiles\uklrygk3.default -> google.com FF Extension: (Disable JavaScript Shared Memory) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uklrygk3.default\features\{d404695e-d501-4d58-b02c-12bfb5393d2c}\disable-js-shared-memory@mozilla.org.xpi [2018-01-19] [Legacy] FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Extension: (ESET Smart Security Extension) - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2016-05-20] [Legacy] [not signed] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-20] () FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-20] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-20] (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-20] () FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-20] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-20] (Oracle Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.) Chrome: ======= CHR StartupUrls: Default -> "hxxps://www.google.com.hk/" CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2018-01-19] CHR Extension: (Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13] CHR Extension: (Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13] CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-20] CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-20] CHR Extension: (Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13] CHR Extension: (IndoXXI Companion) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggmhbeannpfkiafgkfobkanlpaccfdki [2017-10-20] CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-20] CHR Extension: (Chrono Download Manager) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciiogijehkdemklbdcbfkefimifhecn [2017-08-21] CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23] CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-20] CHR Extension: (Chrome Media Router) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-11] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [1810120 2018-01-18] () R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-03-17] (Apple Inc.) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [873248 2010-02-17] (Broadcom Corporation.) R2 camfrog_update_service; C:\Program Files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe [1063968 2016-12-19] (Camshare Inc.) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1343920 2014-09-30] (ESET) S2 KMSServerService; C:\Windows\kmsonboot\HEU_KMS_Service.exe [38454 2013-11-28] () [File not signed] R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes) R2 SpliCamService; C:\Program Files (x86)\SplitCam\SplitCamService.exe [321056 2017-08-21] (SplitCam Co.) S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10803440 2017-12-19] (TeamViewer GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) S2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [240344 2014-09-30] (ESET) U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [240344 2014-09-30] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-09-30] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2014-09-30] (ESET) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77432 2017-11-29] () R0 kavbootc; C:\Windows\System32\drivers\kavbootc64.sys [31848 2016-05-21] (Kingsoft Corporation) R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193968 2018-01-19] (Malwarebytes) R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2018-01-19] (Malwarebytes) R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [46008 2018-01-19] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-01-19] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2018-01-19] (Malwarebytes) S3 RD9700; C:\Windows\System32\DRIVERS\RD9700.sys [21504 2012-05-26] (Corechip Semiconductor, Inc. Co Ltd.) R3 scvad_simple; C:\Windows\System32\drivers\SplitCamAudio.sys [23552 2017-08-11] (Windows (R) Win 7 DDK provider) R3 splitcam_hd_driver; C:\Windows\System32\DRIVERS\splitcam_hd_driver.sys [37600 2017-08-11] (Windows (R) Win 7 DDK provider) U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2018-01-19] () R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [214912 2010-01-27] (Vimicro Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) NETSVCx32: dg597 -> no filepath. ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-01-19 06:50 - 2018-01-19 06:50 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2018-01-19 06:50 - 2018-01-19 06:50 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2018-01-19 06:50 - 2018-01-19 06:50 - 000046008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2018-01-19 06:14 - 2018-01-19 06:14 - 000015423 _____ C:\ComboFix.txt 2018-01-19 06:02 - 2018-01-19 06:14 - 000000000 ____D C:\Qoobox 2018-01-19 06:02 - 2011-06-26 14:45 - 000256000 _____ C:\Windows\PEV.exe 2018-01-19 06:02 - 2010-11-08 01:20 - 000208896 _____ C:\Windows\MBR.exe 2018-01-19 06:02 - 2009-04-20 12:56 - 000060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2018-01-19 06:02 - 2000-08-31 08:00 - 000518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2018-01-19 06:02 - 2000-08-31 08:00 - 000406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2018-01-19 06:02 - 2000-08-31 08:00 - 000098816 _____ C:\Windows\sed.exe 2018-01-19 06:02 - 2000-08-31 08:00 - 000080412 _____ C:\Windows\grep.exe 2018-01-19 06:02 - 2000-08-31 08:00 - 000068096 _____ C:\Windows\zip.exe 2018-01-19 06:01 - 2018-01-19 06:12 - 000000000 ____D C:\Windows\erdnt 2018-01-19 03:18 - 2018-01-19 03:25 - 000000000 ____D C:\AdwCleaner 2018-01-19 02:48 - 2018-01-19 02:48 - 000193968 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2018-01-19 02:47 - 2018-01-19 06:41 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2018-01-19 02:47 - 2018-01-19 02:47 - 000001871 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2018-01-19 02:47 - 2018-01-19 02:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2018-01-19 02:46 - 2017-11-29 09:11 - 000077432 _____ C:\Windows\system32\Drivers\mbae64.sys 2018-01-19 02:45 - 2018-01-19 02:45 - 000000000 ____D C:\ProgramData\Malwarebytes 2018-01-19 02:45 - 2018-01-19 02:45 - 000000000 ____D C:\Program Files\Malwarebytes 2018-01-19 02:27 - 2018-01-19 12:40 - 000000000 ____D C:\FRST 2018-01-19 00:38 - 2018-01-19 00:38 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SplitCam 2018-01-19 00:32 - 2018-01-19 00:39 - 000000000 ____D C:\Users\User\AppData\Roaming\SplitCam 2018-01-19 00:28 - 2018-01-19 00:38 - 000000000 ____D C:\Program Files (x86)\SplitCam 2018-01-19 00:20 - 2018-01-19 00:20 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys 2018-01-19 00:19 - 2018-01-19 00:19 - 000000862 _____ C:\Users\Public\Desktop\RogueKiller.lnk 2018-01-19 00:19 - 2018-01-19 00:19 - 000000000 ____D C:\ProgramData\RogueKiller 2018-01-19 00:19 - 2018-01-19 00:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller 2018-01-19 00:18 - 2018-01-19 00:19 - 000000000 ____D C:\Program Files\RogueKiller 2018-01-19 00:12 - 2018-01-19 06:51 - 000000000 ____D C:\Users\User\AppData\LocalLow\Mozilla 2018-01-19 00:12 - 2018-01-19 00:12 - 000000940 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2018-01-19 00:12 - 2018-01-19 00:12 - 000000928 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2018-01-19 00:12 - 2018-01-19 00:12 - 000000000 ____D C:\Users\User\AppData\Roaming\Mozilla 2018-01-19 00:12 - 2018-01-19 00:12 - 000000000 ____D C:\Users\User\AppData\Local\Mozilla 2018-01-19 00:12 - 2018-01-19 00:12 - 000000000 ____D C:\Program Files\Mozilla Firefox 2018-01-19 00:12 - 2018-01-19 00:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-01-18 23:43 - 2018-01-18 23:46 - 000000000 ____D C:\ProgramData\AnyDesk 2018-01-18 23:43 - 2018-01-18 23:43 - 000001892 _____ C:\Users\Public\Desktop\AnyDesk.lnk 2018-01-18 23:43 - 2018-01-18 23:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyDesk 2018-01-18 23:43 - 2018-01-18 23:43 - 000000000 ____D C:\Program Files (x86)\AnyDesk 2018-01-18 22:50 - 2018-01-18 23:38 - 000000000 ____D C:\Users\User\AppData\Roaming\AnyDesk ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-01-19 06:46 - 2009-07-14 12:45 - 000031280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2018-01-19 06:46 - 2009-07-14 12:45 - 000031280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2018-01-19 06:45 - 2009-07-14 13:13 - 000778150 _____ C:\Windows\system32\PerfStringBackup.INI 2018-01-19 06:45 - 2009-07-14 11:20 - 000000000 ____D C:\Windows\inf 2018-01-19 06:40 - 2009-07-14 13:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2018-01-19 06:12 - 2009-07-14 10:34 - 000000215 _____ C:\Windows\system.ini 2018-01-19 00:11 - 2016-05-20 21:59 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2018-01-18 22:16 - 2017-06-14 22:02 - 000003350 _____ C:\Windows\System32\Tasks\ESET Windows 10 upgrade – Refresh settings 2018-01-18 22:06 - 2017-03-11 00:44 - 000000000 ____D C:\Users\User\AppData\Roaming\Camfrog 2018-01-14 18:00 - 2017-04-23 09:21 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2018-01-09 20:57 - 2016-05-20 22:57 - 000000000 ____D C:\Users\User\AppData\Roaming\Skype 2018-01-09 09:12 - 2016-05-20 22:46 - 000002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-01-09 09:12 - 2016-05-20 22:46 - 000002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-01-07 22:46 - 2017-04-23 09:21 - 000000000 ____D C:\Users\User\AppData\Roaming\TeamViewer 2017-12-26 17:01 - 2017-03-11 00:44 - 000000000 ____D C:\ProgramData\Camfrog Update 2017-12-24 03:37 - 2017-04-23 09:21 - 000000975 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk 2017-12-24 03:37 - 2017-04-23 09:21 - 000000963 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk ==================== Files in the root of some directories ======= 2016-11-03 11:01 - 2016-11-03 11:01 - 007065600 _____ () C:\Program Files (x86)\GUTD8E2.tmp 2016-05-21 18:00 - 2016-05-21 18:00 - 000000021 _____ () C:\Users\User\AppData\Roaming\fixcfg.ini ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed C:\Windows\system32\drivers\eamonm.sys -> Access Denied <======= ATTENTION C:\Windows\system32\drivers\edevmon.sys -> Access Denied <======= ATTENTION C:\Windows\system32\drivers\ehdrv.sys -> Access Denied <======= ATTENTION C:\Windows\system32\drivers\epfwwfpr.sys -> Access Denied <======= ATTENTION LastRegBack: 2018-01-19 02:05 ==================== End of FRST.txt ============================ ---------------------------------------------------------------------------------- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.01.2018 01 Ran by User (19-01-2018 12:43:15) Running from D:\Users\User\Desktop Windows 7 Professional Service Pack 1 (X64) (2016-05-20 13:13:43) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-859187355-2626154896-303692081-500 - Administrator - Disabled) Guest (S-1-5-21-859187355-2626154896-303692081-501 - Limited - Disabled) User (S-1-5-21-859187355-2626154896-303692081-1000 - Administrator - Enabled) => C:\Users\User ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET NOD32 Antivirus 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET NOD32 Antivirus 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated) Adobe Flash Player 21 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated) Adobe Reader XI MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated) AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 3.7.0 - philandro Software GmbH) Apple Application Support (32-bit) (HKLM-x32\...\{05E07D23-91E9-4E70-A4CC-EF505088F967}) (Version: 5.4.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{741291DA-2B34-4D44-8FB6-58EDE21261D8}) (Version: 5.4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{DB18F1C0-846F-46F5-A074-5B97C8AF5C8E}) (Version: 10.3.1.2 - Apple Inc.) Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.) ATI Catalyst Install Manager (HKLM\...\{E2F5EAC1-DC02-4886-C7AC-AE7340815674}) (Version: 3.0.762.0 - ATI Technologies, Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Camfrog Video Chat 6.19 (HKLM-x32\...\Camfrog) (Version: 6.19.649 - Camshare, Inc.) ccc-core-static (HKLM-x32\...\{AE2C34DE-20D1-B68D-82FD-CB60B9C5BA3D}) (Version: 2010.0113.2208.39662 - ATI) Hidden ESET NOD32 Antivirus (HKLM\...\{E9A50574-3422-45A8-8FC2-2C74408467EA}) (Version: 7.0.325.1 - ESET, spol s r. o.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden iTunes (HKLM\...\{6C01A0A7-7440-4D48-93C6-2927A1E93FE6}) (Version: 12.6.0.100 - Apple Inc.) Java 8 Update 91 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.14 - Oracle Corporation) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation) K-Lite Codec Pack 9.4.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.4.0 - ) Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.1400 - Broadcom Corporation) Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 1.10.01.29.1 - Vimicro) Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 57.0.4 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0.4 (x64 en-US)) (Version: 57.0.4 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 57.0.4 - Mozilla) QQ International (HKLM-x32\...\{3CA54984-A14B-42FE-9FF1-7EA90151D725}) (Version: 1.91.1369.0 - Tencent Technology(Shenzhen) Company Limited) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6093 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30116 - Realtek Semiconductor Corp.) RogueKiller version 12.12.0.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.0.0 - Adlice Software) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) SplitCam (HKLM-x32\...\SplitCam) (Version: 7.7.4.1 - SplitCam Co) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.90922 - TeamViewer) Windows Driver Package - Broadcom (BTHUSB) Bluetooth (02/25/2010 6.2.0.9419) (HKLM\...\85CE3A3657FAE5FD305B143E90E6FC89BA53001C) (Version: 02/25/2010 6.2.0.9419 - Broadcom) Windows Driver Package - Broadcom Bluetooth (01/19/2010 6.2.0.1417) (HKLM\...\7341A1B43E7FE58942EB1E820A17C18305DFBCE6) (Version: 01/19/2010 6.2.0.1417 - Broadcom) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom) WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - ) Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2014-09-30] (ESET) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-03-15] () ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-03-15] () ContextMenuHandlers2: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2014-09-30] (ESET) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes) ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-03-15] () ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-03-15] () ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2010-01-13] (Advanced Micro Devices, Inc.) ContextMenuHandlers6: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2014-09-30] (ESET) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-03-15] () ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-03-15] () ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {26DA7A01-F82E-490A-A265-E8665B7338D8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.) Task: {358036C5-CDD7-4EF6-B6BB-4F29C79DE9D5} - System32\Tasks\ESET Windows 10 upgrade – Refresh settings => C:\Program Files\Common Files\AV\ESET NOD32 Antivirus 7.0\upgrade.exe [2017-10-30] (ESET) Task: {7CC01537-7DFF-40F4-B770-A280DADC3C37} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-20] (Google Inc.) Task: {888D79D9-B3E7-4A00-AF9E-26FF9A0CA419} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-20] (Google Inc.) Task: {A76D9E4D-811C-4994-BBFF-496D8849E3C8} - System32\Tasks\HEU_KMS_Service_ONSTART => C:\Windows\kmsonboot\autoact.exe [2013-11-28] (HEU CNST) Task: {BA6BDA3A-1FAC-4D99-919E-DCE183F16291} - System32\Tasks\HEU_KMS_Service_WEEKLY => C:\Windows\kmsonboot\autoact.exe [2013-11-28] (HEU CNST) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2018-01-18 23:43 - 2018-01-18 22:50 - 001810120 _____ () C:\Program Files (x86)\AnyDesk\AnyDesk.exe 2017-03-16 16:08 - 2017-03-16 16:08 - 001354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2017-03-16 16:08 - 2017-03-16 16:08 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 001354040 _____ () C:\Program Files\iTunes\libxml2.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll 2010-02-17 23:26 - 2010-02-17 23:26 - 000173344 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll 2018-01-19 02:46 - 2017-11-29 09:11 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2018-01-19 02:46 - 2017-11-29 09:11 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2017-12-22 17:36 - 2017-12-22 17:36 - 000772104 _____ () C:\Program Files (x86)\Camfrog\Camfrog Video Chat\camfrog_cef.exe 2016-05-13 15:59 - 2016-05-13 15:59 - 048936448 _____ () C:\Program Files (x86)\Camfrog\Camfrog Video Chat\libcef.dll 2017-10-20 20:50 - 2017-10-20 20:50 - 000345600 _____ () C:\Program Files (x86)\Camfrog\Camfrog Video Chat\opus.dll 2016-05-13 15:59 - 2016-05-13 15:59 - 001665024 _____ () C:\Program Files (x86)\Camfrog\Camfrog Video Chat\libglesv2.dll 2016-05-13 15:59 - 2016-05-13 15:59 - 000075264 _____ () C:\Program Files (x86)\Camfrog\Camfrog Video Chat\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 10:34 - 2018-01-19 06:12 - 000000027 _____ C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-859187355-2626154896-303692081-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: AMD External Events Utility => 2 MSCONFIG\Services: TeamViewer => 2 MSCONFIG\startupreg: Energy Management => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe MSCONFIG\startupreg: EnergyUtility => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe MSCONFIG\startupreg: RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{B9AC4A1B-06C3-40D5-8D04-8AC0B0AED259}] => (Allow) LPort=1688 FirewallRules: [{019A6368-80B8-48D8-86C1-259A7714F6E3}] => (Allow) LPort=1688 FirewallRules: [{9DAB13FF-16BD-4F23-8667-DFED93508404}] => (Allow) C:\Windows\kmsonboot\HEU_KMS_Service.exe FirewallRules: [{1CF50D46-2DF2-4A83-BB04-3413C78B13AA}] => (Allow) C:\Windows\kmsonboot\HEU_KMS_Service.exe FirewallRules: [{E3ABE9D9-E2C6-466C-8CCF-64BAF95AE100}] => (Allow) C:\Windows\system32\sppsvc.exe FirewallRules: [{19701D8B-690B-434C-86F9-DDAC4359DD37}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{9603F196-358C-461F-96F4-6062903766AC}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{0C8028DE-5744-4B48-9556-EA7E5B0F32F9}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{2C4F649D-7C74-4D88-AA57-5D7AA2C72B7C}] => (Allow) C:\Program Files (x86)\MyDrivers\DriverGenius\xlmodule\download\minithunderplatform.exe FirewallRules: [{1F489D81-DC3D-4F3C-A533-418FF700F464}] => (Allow) C:\Program Files (x86)\MyDrivers\DriverGenius\xlmodule\download\minithunderplatform.exe FirewallRules: [TCP Query User{D907E9C6-30AF-4193-94AE-71E2D4D25EA8}C:\program files (x86)\camfrog\camfrog video chat\camfrog video chat.exe] => (Block) C:\program files (x86)\camfrog\camfrog video chat\camfrog video chat.exe FirewallRules: [UDP Query User{96231707-EB10-42B5-BEB7-F9384B46F1FA}C:\program files (x86)\camfrog\camfrog video chat\camfrog video chat.exe] => (Block) C:\program files (x86)\camfrog\camfrog video chat\camfrog video chat.exe FirewallRules: [{7E87FB37-98D0-4F4C-843F-308CCB83701B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{62E7F7C2-D02E-483B-9E61-DBBEE110B7A2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C34C8F84-8581-4512-A3B6-E9E2BCAC9D97}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{F4B6FE27-EA9F-4298-A97E-76BA443026E1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E13B76D3-5C7E-4908-B358-959A4376C297}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{EB6DBF8B-42D6-4AFC-ADF1-D8E3C6DBA8FE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{64FBD319-95B2-435A-8401-AA8CA37314EC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{170FF740-1A48-4766-8176-90C83702F03A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{DF901147-834B-46D0-AAAA-973D82163281}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{97BC348B-50CA-4F6E-9742-B96B655A6330}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{5CAAD798-A3CB-4116-B4BD-063CEE3A4499}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{1A78C8D5-3C0D-48B4-B38A-6B6DB1BDFDA5}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{A910F8B4-553D-4859-B6F2-F049621CDBD4}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{6EF22FE5-FAF3-40B2-88B4-A51B59020C61}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{AA3F3FC0-11C5-445D-B0F5-381C7EA62CA3}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{45CC30C7-D629-40CC-ACAD-97E21718D31E}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{69CB1B3B-0BF6-4B12-933C-63DD268B1068}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{3F4575FC-84C5-4511-B7AD-E546BD78DABA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{38248528-CF25-4A7F-9DC4-3E656817DCA7}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{19DE4AEE-9F75-4A49-AFB5-F748B95AC4D1}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{70B286E7-F72C-41B7-9203-E8E8E7C9F96D}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{3B2468FF-E79C-44D2-A3AD-47C956226ED9}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{7B38CAE2-C21E-405F-8604-48B6F9C7F9F6}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{A0A1938F-8042-4270-8FD4-C5E424C576E7}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe ==================== Restore Points ========================= 09-12-2017 19:02:48 Scheduled Checkpoint 19-12-2017 16:29:34 Scheduled Checkpoint 26-12-2017 19:50:17 Scheduled Checkpoint 03-01-2018 00:00:04 Scheduled Checkpoint 19-01-2018 00:06:32 Removed Energy Management 19-01-2018 00:29:38 Device Driver Package Install: SplitCam Sound, video and game controllers ==================== Faulty Device Manager Devices ============= Name: Lexmark X422 Description: Lexmark X422 Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Lexmark Service: usbscan Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/19/2018 06:42:19 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/19/2018 03:27:52 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/19/2018 02:47:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 02:47:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 02:47:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 01:39:38 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/19/2018 12:31:22 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:31:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:31:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:31:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . System errors: ============= Error: (01/19/2018 06:41:21 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (01/19/2018 06:40:55 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error: The system cannot find the file specified. Error: (01/19/2018 06:12:11 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error: (01/19/2018 06:11:28 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. Error: (01/19/2018 06:08:33 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Error: (01/19/2018 03:26:49 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (01/19/2018 03:26:27 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error: The system cannot find the file specified. Error: (01/19/2018 03:25:29 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\System32\bcmihvsrv64.dll Error: (01/19/2018 03:25:29 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\System32\bcmihvsrv64.dll Error: (01/19/2018 03:25:27 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\System32\bcmihvsrv64.dll CodeIntegrity: =================================== Date: 2018-01-19 06:11:28.914 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-01-19 06:11:28.889 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2018-01-19 05:11:52.471 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-19 05:11:49.010 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-19 05:11:48.462 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-19 05:11:48.276 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-19 03:38:24.023 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-19 03:37:16.488 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-19 03:36:57.943 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-19 03:36:50.657 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: AMD Athlon(tm) II Neo K125 Processor Percentage of memory in use: 52% Total physical RAM: 3838.17 MB Available physical RAM: 1837.79 MB Total Virtual: 7674.52 MB Available Virtual: 5345.63 MB ==================== Drives ================================ Drive c: (Win7) (Fixed) (Total:150.01 GB) (Free:112.33 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:82.87 GB) (Free:82.12 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 232.9 GB) (Disk ID: 000885B3) Partition 1: (Active) - (Size=150 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=82.9 GB) - (Type=OF Extended) ==================== End of Addition.txt ============================
  6. Finished, I did not need use Rkill. Here is the combofix log: ComboFix 18-01-10.01 - User 01/19/2018 6:04.1.1 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3838.2250 [GMT 8:00] Running from: d:\users\User\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 7.0 *Disabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289} AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B} SP: ESET NOD32 Antivirus 7.0 *Disabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\User\AppData\Roaming\Microsoft\Windows\Recent\Facebook.url c:\windows\msdownld.tmp . . ((((((((((((((((((((((((( Files Created from 2017-12-18 to 2018-01-18 ))))))))))))))))))))))))))))))) . . 2018-01-18 22:12 . 2018-01-18 22:12 -------- d-----w- c:\users\Default\AppData\Local\temp 2018-01-18 19:18 . 2018-01-18 19:25 -------- d-----w- C:\AdwCleaner 2018-01-18 18:48 . 2018-01-18 18:48 193968 ----a-w- c:\windows\system32\drivers\MbamChameleon.sys 2018-01-18 18:47 . 2018-01-18 19:26 253880 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2018-01-18 18:46 . 2017-11-29 01:11 77432 ----a-w- c:\windows\system32\drivers\mbae64.sys 2018-01-18 18:45 . 2018-01-18 18:45 -------- d-----w- c:\programdata\Malwarebytes 2018-01-18 18:45 . 2018-01-18 18:45 -------- d-----w- c:\program files\Malwarebytes 2018-01-18 18:27 . 2018-01-18 18:30 -------- d-----w- C:\FRST 2018-01-18 16:32 . 2018-01-18 16:39 -------- d-----w- c:\users\User\AppData\Roaming\SplitCam 2018-01-18 16:28 . 2018-01-18 16:38 -------- d-----w- c:\program files (x86)\SplitCam 2018-01-18 16:20 . 2018-01-18 16:20 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys 2018-01-18 16:19 . 2018-01-18 16:19 -------- d-----w- c:\programdata\RogueKiller 2018-01-18 16:18 . 2018-01-18 16:19 -------- d-----w- c:\program files\RogueKiller 2018-01-18 16:12 . 2018-01-18 16:12 -------- d-----w- c:\users\User\AppData\Local\Mozilla 2018-01-18 16:12 . 2018-01-18 16:12 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service 2018-01-18 16:12 . 2018-01-18 16:12 -------- d-----w- c:\program files\Mozilla Firefox 2018-01-18 15:43 . 2018-01-18 15:46 -------- d-----w- c:\programdata\AnyDesk 2018-01-18 15:43 . 2018-01-18 15:43 -------- d-----w- c:\program files (x86)\AnyDesk 2018-01-18 14:50 . 2018-01-18 15:38 -------- d-----w- c:\users\User\AppData\Roaming\AnyDesk . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2016-11-03 03:01 . 2016-11-03 03:01 7065600 ----a-w- c:\program files (x86)\GUTD8E2.tmp . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-23 926896] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-03-31 596504] "331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2010-01-15 536576] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AnyDesk.lnk - c:\program files (x86)\AnyDesk\AnyDesk.exe --control [2018-1-18 1810120] Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2010-2-17 1083680] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 KMSServerService;HEU_KMS_Service;c:\windows\kmsonboot\HEU_KMS_Service.exe;c:\windows\kmsonboot\HEU_KMS_Service.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys;c:\windows\SYSNATIVE\DRIVERS\AcpiVpc.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 RD9700;RD9700 USB2.0 To Fast Ethernet Adapter;c:\windows\system32\DRIVERS\RD9700.sys;c:\windows\SYSNATIVE\DRIVERS\RD9700.sys [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S0 kavbootc;kavbootc;c:\windows\system32\drivers\kavbootc64.sys;c:\windows\SYSNATIVE\drivers\kavbootc64.sys [x] S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x] S2 AnyDesk;AnyDesk Service;c:\program files (x86)\AnyDesk\AnyDesk.exe;c:\program files (x86)\AnyDesk\AnyDesk.exe [x] S2 Apple Mobile Device Service;Apple Mobile Device Service;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe;c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [x] S2 camfrog_update_service;Camfrog Update Service;c:\program files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe;c:\program files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe [x] S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x] S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x] S2 MBAMChameleon;MBAMChameleon;c:\windows\System32\Drivers\MbamChameleon.sys;c:\windows\SYSNATIVE\Drivers\MbamChameleon.sys [x] S2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x] S2 SpliCamService;SplitCamService;c:\program files (x86)\SplitCam\SplitCamService.exe;c:\program files (x86)\SplitCam\SplitCamService.exe [x] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys;c:\windows\SYSNATIVE\drivers\btusbflt.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\Drivers\mbamswissarmy.sys;c:\windows\SYSNATIVE\Drivers\mbamswissarmy.sys [x] S3 scvad_simple;SplitCam Virtual Microphone (WDM);c:\windows\system32\drivers\SplitCamAudio.sys;c:\windows\SYSNATIVE\drivers\SplitCamAudio.sys [x] S3 splitcam_hd_driver;SplitCam Virtual Video Driver;c:\windows\system32\DRIVERS\splitcam_hd_driver.sys;c:\windows\SYSNATIVE\DRIVERS\splitcam_hd_driver.sys [x] S3 vm331avs;Digital Camera 1;c:\windows\system32\Drivers\vm331avs.sys;c:\windows\SYSNATIVE\Drivers\vm331avs.sys [x] . . --- Other Services/Drivers In Memory --- . *Deregistered* - ESProtectionDriver *Deregistered* - MBAMFarflt *Deregistered* - MBAMProtection *Deregistered* - MBAMWebProtection . HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs dg597 . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2014-09-30 5549768] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-04-20 10151968] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2017-03-22 303928] . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = https://us.yahoo.com/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uklrygk3.default\ FF - prefs.js: browser.startup.homepage - google.com . - - - - ORPHANS REMOVED - - - - . HKLM_Wow6432Node-ActiveSetup-{8A69D345-D564-463c-AFF1-A69D9E530F96} - c:\program files (x86)\Google\Chrome\Application\57.0.2987.133\Installer\chrmstp.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_21_0_0_242_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_21_0_0_242_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_21_0_0_242_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_21_0_0_242_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_242.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.21" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_242.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_242.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_21_0_0_242.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2018-01-19 06:14:41 ComboFix-quarantined-files.txt 2018-01-18 22:14 . Pre-Run: 120,238,850,048 bytes free Post-Run: 120,515,514,368 bytes free . - - End Of File - - A833AA02910E3F9237611D4AA3659AF8 09CE7397AF23D4C0B331B89D0297CC7E
  7. Thank you, here is logs: RogueKiller V12.12.0.0 (x64) [Jan 15 2018] (Free) by Adlice Software mail : http://www.adlice.com/contact/ Feedback : https://forum.adlice.com Website : http://www.adlice.com/download/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : User [Administrator] Started from : C:\Program Files\RogueKiller\RogueKiller64.exe Mode : Delete -- Date : 01/19/2018 00:20:53 (Duration : 01:11:43) ¤¤¤ Processes : 1 ¤¤¤ [Proc.Injected] dwm.exe(1892) -- C:\Windows\System32\dwm.exe[7] -> [NoKill] ¤¤¤ Registry : 8 ¤¤¤ [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {93F82C07-2C13-4470-AD2E-AC02BB9C9FD1} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\User\AppData\Local\Temp\HEU_KMS_Mini76\HEU_KMS_Service.exe|Name=HEU_KMS_Service| [x] -> Deleted [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {B6154BB2-7BD4-478B-A168-DA162D33298A} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\User\AppData\Local\Temp\HEU_KMS_Mini76\HEU_KMS_Service.exe|Name=HEU_KMS_Service| [x] -> Deleted [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {93F82C07-2C13-4470-AD2E-AC02BB9C9FD1} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\Users\User\AppData\Local\Temp\HEU_KMS_Mini76\HEU_KMS_Service.exe|Name=HEU_KMS_Service| [x] -> Deleted [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {B6154BB2-7BD4-478B-A168-DA162D33298A} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\Users\User\AppData\Local\Temp\HEU_KMS_Mini76\HEU_KMS_Service.exe|Name=HEU_KMS_Service| [x] -> Deleted [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Replaced (2) [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Replaced (2) [PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-859187355-2626154896-303692081-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Replaced (1) [PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-859187355-2626154896-303692081-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Replaced (1) ¤¤¤ Tasks : 0 ¤¤¤ ¤¤¤ Files : 4 ¤¤¤ [PUP.Gen1][File] C:\Users\Public\Desktop\Tencent QQ.lnk [LNK@] C:\PROGRA~2\Tencent\QQIntl\Bin\QQ.exe -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\IM\1033 -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\IM -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\Logs\QQ.tlg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\Logs\QQSetupEx.tlg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\Logs\qq_setup.log -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\Logs\regsvr32.tlg -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\Logs -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ\commonf_inst\TXSSOSetup.exe -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\commonf_inst -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\Misc -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\BackupDLTmp\Download\QzoneMusicInstall.exe.tdl -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\BackupDLTmp\Download -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\BackupDLTmp -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\SetupEx~0\QQSetupEx.exe -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\SetupEx~0\vqqsdl.dll -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\SetupEx~0 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\Uninstall\47.83.0.4819.0\QQ.msi -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\Uninstall\47.83.0.4819.0\Uninstall.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\Uninstall\47.83.0.4819.0 -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp\Uninstall -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\STemp -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ\Temp -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\3GMobileQQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\3GMobileQQ14.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\3GMobileQQ20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\3GMobileQQAway10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\3GMobileQQAway20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\iPhoneQQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\iPhoneQQ14.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\iPhoneQQ20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\iPhoneQQPush10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\iPhoneQQPush20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQ13.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQ14.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQ20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQAway20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQBusy20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQPush10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQPush13.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MobileQQPush20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MQQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MQQ14.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\MQQ20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PadQQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PadQQ14.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PadQQ20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PadQQAway10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PadQQAway20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQaway10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQAway20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQBusy10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQBusy20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQInvisible10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQInvisible20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQMute10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQMute20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQQme10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\PCQQQme20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\TVQQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\TVQQ14.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\TVQQ20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WapMobileQQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WapMobileQQ20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WebQQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WebQQ14.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WebQQ20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WebQQAway10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WebQQAway20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WebQQBusy20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WebQQMute20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WebQQQme20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WeiXin10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WeiXin14.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WeiXin20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WeiXinPush10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\WeiXinPush20.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\Win8QQ10.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType\Win8QQ20.png -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc\ClientType -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Misc -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_16\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_16\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_16\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_16 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_17\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_17\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_17\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_17 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_18\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_18\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_18\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_18 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_19\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_19\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_19\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_19 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_20\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_20\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_20\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_20 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_21\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_21\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_21\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_21 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_22\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_22\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_22\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_22 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_23\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_23\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_23\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_23 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_24\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_24\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_24\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_24 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_25\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_25\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_25\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_25 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_26\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_26\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_26\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_26 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_27\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_27\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_27\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_27 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_28\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_28\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_28\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_28 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_29\main.jpg -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_29\preview.png -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_29\themeconfig.xml -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system\1.45_29 -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins\system -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009\Skins -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\QQ2009 -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\TXSSO\SetupLogs\nsis.log -> Deleted [PUP.Gen1][File] C:\Users\User\AppData\Roaming\Tencent\TXSSO\SetupLogs\setuplog.log -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\TXSSO\SetupLogs -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\TXSSO\SSOTemp -> Deleted [PUP.Gen1][Folder] C:\Users\User\AppData\Roaming\Tencent\TXSSO -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\af.xml.txd -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\app.xml.txd -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\ABL.sys -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AddEmotion.htm -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AddrSearch.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AdvVideoDev.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AFBase.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AFCtrl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AFUtil.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AppCom.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AppFramework.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\Applaunch.prf -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AppMisc.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\AppUtil.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkEngine.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkFS.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkGraphic.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkHTTP.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkImage.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkIOStub.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkIPC.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkModule.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkScript.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkShell.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\arkXML.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\Auvqqsdl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\avcodec-53.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\avformat-53.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\avutil-51.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\bugreport.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\Camera.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\ChatFrameApp.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\Common.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\ConfigCenter.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\ContactInfoFrame.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\ContactMgr.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\CPHelper.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\CustomFace.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\Extract.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\FacePackageDll.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\FlashService.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\GF.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\GroupApp.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\HummerEngine.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\icudt.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\IM.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\InformationBox.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\iobitdownloader.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\IPC.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\jgImage.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\jsonc.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\KernelMisc.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\KernelUtil.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\libcef.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\libcurl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\libexpat.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\libexpatw.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\libjpegturbo.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\libpng.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\bsdiff -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\chromium -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\dmg_fp -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\dynamic_annotations -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\google-url -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\icu -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\libvpx -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\lzma -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\modp_b64 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\nspr -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\protobuf-lite -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\speex -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE\xdg_user_dirs -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin\LICENSE -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\locales\zh-CN.pak -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin\locales -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LoginPanel.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\LongCnn.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\lua.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\MainFrame.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\MsgMgr.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\msvcp60.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\OPIEModule.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\OPWebKitClient.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\OPWebKitClientProxyPS.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\OPWebKitCtrl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\PBL.sys -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\PluginCommon.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\plugins\NP_GFControl.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin\plugins -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\PreloginLogic.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\ProcessSession.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\QInterLive.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\QQ.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\QQApp.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\QQExternal.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\QQPI.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\QQService.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\RequestHost.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\RHComm.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\RICHED20.DLL -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\SCCore.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\SetupEx\QQSetupEx.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\SetupEx\vqqsdl.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin\SetupEx -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\SkinMgr.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\sqlite.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\StorageTool.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\SystemMsg.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TaskTray.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TcVpxDec.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TcVpxEnc.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\Tencentdl.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\Timwp.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\Timwp.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\tinyxml.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TNProxy.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TSEH.DAT -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TSIP.DAT -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TSSafeEdit.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXPFProxy.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXPlatform.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\bin\npSSOAxCtrlForPTLogin.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\bin\SSOCommon.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\bin\SSOLUIControl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\bin\SSOPlatform.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\I18N\2052\PGFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\I18N\2052\SSOStringBundle.xml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\I18N\2052 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\I18N\SSOConfig.xml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO\I18N -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin\TXSSO -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\UtilGif.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\vi.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\VQQProto.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\vqqsdl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\VQQTrace.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\WebKitCtrl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\XFQueryResource.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\xGraphic32.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\xImage.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\xplatformex.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\XVEngine.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Bin\zlib.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\common.xml.txd -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\gf-config-postlogin.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\gf-config.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\AFPreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\AFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\BaseStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\BaseUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\CommonString.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\CommonUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\CustomFaceShortcut.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\DGM.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\FingerStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\FontList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\GroupLayer.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\I18NBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\I18NUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\LangList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\LocList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\PGFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\PreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\StringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\tradelist.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028\UrlBundle.xml.enc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\I18N\1028 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\AFPreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\AFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\BaseStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\BaseUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\CommonString.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\CommonUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\CustomFaceShortcut.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\DGM.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\FingerStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\FontList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\GroupLayer.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\I18NBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\I18NUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\LangList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\LocList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\PGFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\PreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\StringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\tradelist.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031\UrlBundle.xml.enc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\I18N\1031 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\AFPreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\AFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\BaseStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\BaseUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\CommonString.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\CommonUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\CustomFaceShortcut.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\DGM.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\FingerStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\FontList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\GroupLayer.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\I18NBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\I18NUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\LangList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\LocList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\PGFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\PreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\StringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\tradelist.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033\UrlBundle.xml.enc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\I18N\1033 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\AFPreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\AFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\BaseStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\BaseUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\CommonString.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\CommonUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\CustomFaceShortcut.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\DGM.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\FingerStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\FontList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\GroupLayer.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\I18NBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\I18NUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\LangList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\LocList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\PGFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\PreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\StringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\tradelist.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036\UrlBundle.xml.enc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\I18N\1036 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\AFPreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\AFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\BaseStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\BaseUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\CommonString.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\CommonUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\CustomFaceShortcut.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\DGM.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\FingerStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\FontList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\GroupLayer.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\I18NBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\I18NUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\LangList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\LocList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\PGFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\PreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\StringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\tradelist.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041\UrlBundle.xml.enc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\I18N\1041 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\AFPreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\AFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\BaseStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\BaseUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\CommonString.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\CommonUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\CustomFaceShortcut.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\DGM.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\FingerStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\FontList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\GroupLayer.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\I18NBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\I18NUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\LangList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\LocList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\PGFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\PreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\StringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\tradelist.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042\UrlBundle.xml.enc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\I18N\1042 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\AFPreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\AFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\BaseStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\BaseUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\CommonString.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\CommonUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\CustomFaceShortcut.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\DGM.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\FingerStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\FontList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\GroupLayer.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\I18NBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\I18NUrlBundle.xml.enc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\LangList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\LocList.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\PGFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\PreLoadStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\StringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\tradelist.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082\UrlBundle.xml.enc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\I18N\3082 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\config1028.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\config1031.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\config1033.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\config1036.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\config1041.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\config1042.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\I18N\config3082.xml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\I18N -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\kernel.xml.txd -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\1\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\1\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\1\7 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\10\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\11\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13\8 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\14\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\14\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\14\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\14\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\2\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\2\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\3\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\4\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\5\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\5\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\16 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\20 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\8\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\8\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\8\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\8\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\8\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\12 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\19 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\6 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1028 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\1\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\1\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\1\7 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\10\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\11\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13\8 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\14\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\14\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\14\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\14\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\2\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\2\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\3\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\4\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\5\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\5\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\16 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\20 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\8\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\8\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\8\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\8\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\8\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\12 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\19 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\6 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1031 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\1\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\1\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\1\7 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\10\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\11\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13\8 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\14\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\14\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\14\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\14\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\2\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\2\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\3\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\4\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\5\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\5\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\16 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\20 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\8\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\8\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\8\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\8\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\8\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\12 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\19 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\6 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1033 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\1\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\1\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\1\7 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\10\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\11\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13\8 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\14\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\14\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\14\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\14\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\2\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\2\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\3\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\4\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\5\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\5\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\16 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\20 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\8\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\8\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\8\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\8\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\8\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\12 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\19 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\6 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1036 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\1\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\1\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\1\7 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\10\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\11\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13\8 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\14\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\14\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\14\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\14\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\2\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\2\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\3\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\4\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\5\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\5\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\16 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\20 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\8\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\8\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\8\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\8\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\8\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\12 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\19 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\6 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1041 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\1\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\1\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\1\7 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\10\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\11\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13\8 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\14\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\14\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\14\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\14\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\2\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\2\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\3\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\4\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\5\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\5\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\16 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\20 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\8\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\8\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\8\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\8\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\8\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\12 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\19 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\6 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\1042 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\1\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\1\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\1\7 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\10\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\11\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13\8 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\14\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\14\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\14\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\14\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\2\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\2\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\3\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\4\1 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\5\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\5\2 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\11 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\14 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\16 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\2 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\20 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\8\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\8\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\8\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\8\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\8\6 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\1 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\10 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\12 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\13 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\15 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\17 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\18 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\19 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\3 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\4 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\5 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\6 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\7 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\8 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082\9 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC\3082 -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\CSC -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\LNNEsc\defaultTips\tips.html -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\LNNEsc\defaultTips\Tips_I_back2.bmp -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\LNNEsc\defaultTips -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\LNNEsc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\Sound\Classic\Audio.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\Sound\Classic\Global.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\Sound\Classic\msg.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\Sound\Classic\shake.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\Sound\Classic\system.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Misc\Sound\Classic\tweet.wav -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\Sound\Classic -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc\Sound -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Misc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\platform1028.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\platform1031.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\platform1033.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\platform1036.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\platform1041.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\platform1042.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\platform3082.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\anyvision.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\audioengine.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\audioengine32.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\AudioVideo.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\fm.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\GIPSVoiceEngineDLL.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\GIPSVoiceEngineDLL_MD.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\haar_face_1.dat -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\IntelDec.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\IntelEnc.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\MediaEngine.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\Qpl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\RoomEngine.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\SessionLogic.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\TRAE.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\VCodec.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\VideoDevice.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\VP8.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\VQQ2.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\VqqAllInOne.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\VQQConv2.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\VQQGroup.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\VQQTrace2.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin\xplatform.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\Bundle.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\Misc\GAudio_Call.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\Misc\GAudio_Receive.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\Misc\SoundTest.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\Misc\VideoShow_Countdown.wav -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\Misc\VideoShow_TakePic.wav -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo\Misc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.AudioVideo -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.FileTransfer\Bin\FileTransfer.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.FileTransfer\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.FileTransfer\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.FileTransfer -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Graffito\Bin\Graffito.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Graffito\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Graffito\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Graffito -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Mail\Bin\Mail.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Mail\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Mail\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Mail -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Memo\Bin\Memo.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Memo\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Memo\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Memo -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.NetDisk\Bin\DiskLite.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.NetDisk\Bin\NetDisk.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.NetDisk\Bin\TXFTNActiveX.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.NetDisk\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.NetDisk\Bundle.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.NetDisk\gf-config.xml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.NetDisk -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Bin\FlashPlayer.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Bin\Qzone.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Bundle.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\common.xml.txd -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\FlashPlayer.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\gf-config.xml.txd -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\1028\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\1028\StringBundle.xml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\1028 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\1033\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\1033\StringBundle.xml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\1033 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\2052\GFStringBundle.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\2052\StringBundle.xml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\2052 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\config.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N\StringState.xml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\I18N -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\Res.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\Xtml\flashplayerwnd.xml.gmd -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer\Xtml -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\FlashPlayer -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Misc\qzonepackage\blog -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Misc\qzonepackage\common -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Misc\qzonepackage\notepad -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Misc\qzonepackage\photo -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Misc\qzonepackage -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone\Misc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Qzone -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin\Base.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin\Capture.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin\CaptureHelper.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin\Media.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin\Net.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin\RemoteControl.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin\RemoteProxy.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin\Remoting.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteControl -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteHelp\Bin\RemoteHelp.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteHelp\Bin\RHCommV.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteHelp\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteHelp\Bundle.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteHelp\Misc\desktop_view.cur -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteHelp\Misc -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.RemoteHelp -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.SNSApp\Bin\SNSApp.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.SNSApp\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.SNSApp\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.SNSApp -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.VAS\bin\TRCloudInputLib.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.VAS\bin\VAS.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.VAS\bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.VAS\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.VAS -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.WBlog\Bin\WBKernel.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.WBlog\Bin\WBlog.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.WBlog\Bin\WBMisc.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.WBlog\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.WBlog\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.WBlog -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Weather\Bin\Weather.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Weather\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Weather\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Weather -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Winks\bin\Winks.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Winks\bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Winks\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Winks -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Wireless\Bin\Wireless.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Wireless\Bin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Wireless\Bundle.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin\Com.Tencent.Wireless -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\pluginList.db -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Plugin\pluginlist.tpc.txd -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Plugin -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\QQLicense.txt -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\QQUninst.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\QQWhatsnew.txt -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Data.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Res.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Themes\Default.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Themes -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Xtml1028.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Xtml1031.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Xtml1033.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Xtml1036.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Xtml1041.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Xtml1042.rdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369\Xtml3082.rdb -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl\Resource.1.91.1369 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Timwp.xml.txd -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Timwp_gf.tpc -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\txupd.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\Uninstall.xml -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\xgui.xml.txd -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Tencent\QQIntl\???QQ???.txt -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Tencent\QQIntl -> Deleted [PUP.Gen1][File] C:\Users\Public\Desktop\Tencent QQ.lnk [LNK@] C:\PROGRA~2\Tencent\QQIntl\Bin\QQ.exe -> Removed at reboot [2] ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Hosts File : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤ ¤¤¤ Web browsers : 0 ¤¤¤ ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: Hitachi HTS545025B9A300 ATA Device +++++ --- User --- [MBR] 83131f81037af17ec5f47fb909d95c66 [BSP] 9f18509982afac578aa3bd5460f45663 : Windows XP|VT.Unknown MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 153610 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 314597376 | Size: 84863 MB User = LL1 ... OK User = LL2 ... OK ---------------------------------------------------------------------------- Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 1/19/18 Scan Time: 3:01 AM Log File: 0c4f9ace-fc82-11e7-bf04-c0cb38e8b525.json Administrator: Yes -Software Information- Version: 3.3.1.2183 Components Version: 1.0.262 Update Package Version: 1.0.3726 License: Trial -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: User-PC\User -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 254283 Threats Detected: 0 (No malicious items detected) Threats Quarantined: 0 (No malicious items detected) Time Elapsed: 14 min, 7 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 0 (No malicious items detected) Physical Sector: 0 (No malicious items detected) (end) ----------------------------------------------------------- # AdwCleaner 7.0.6.0 - Logfile created on Thu Jan 18 19:25:18 2018 # Updated on 2017/21/12 by Malwarebytes # Running on Windows 7 Professional (X64) # Mode: clean # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services deleted. ***** [ Folders ] ***** Deleted: C:\Program Files (x86)\Common Files\Tencent Deleted: C:\Users\All Users\Documents\Tencent Deleted: C:\Users\Public\Documents\Tencent ***** [ Files ] ***** No malicious files deleted. ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** No malicious tasks deleted. ***** [ Registry ] ***** Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{AEA364D7-C7A1-414A-9AED-DB8F8E62B3D9} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{E439517B-D1A8-4656-A069-D51AA06DFB69} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2DFDD66E-587A-4FB4-AF4D-BD022E63ABD7} Deleted: [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{065B2555-C998-409F-8960-D4DCC5265157} Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1} Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E} Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE Deleted: [Key] - HKLM\SOFTWARE\MozillaPlugins\@qq.com\TXSSO Deleted: [Key] - HKLM\SOFTWARE\MozillaPlugins\@qq.com\npqscall Deleted: [Key] - HKLM\SOFTWARE\MozillaPlugins\@qq.com\npchrome ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries deleted. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries deleted. ************************* ::Tracing keys deleted ::Winsock settings cleared ::Additional Actions: 0 ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [2229 B] - [2018/1/18 19:22:30] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########
  8. I'm working with a friend Win 7 and having problems staying connected via remote and the antivirus wont update. I think there is something stopping it, take a look please. Here is FRST: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17.01.2018 01 Ran by User (administrator) on USER-PC (19-01-2018 02:27:28) Running from D:\Users\User\Desktop Loaded Profiles: User (Available Profiles: User) Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe (Camshare Inc.) C:\Program Files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (SplitCam Co.) C:\Program Files (x86)\SplitCam\SplitCamService.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe () C:\Program Files (x86)\AnyDesk\AnyDesk.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (SplitCam Co.) C:\Program Files (x86)\SplitCam\SplitCam.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5549768 2014-09-30] (ESET) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1890088 2009-12-10] (Synaptics Incorporated) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10151968 2010-04-20] (Realtek Semiconductor) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-03-22] (Apple Inc.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation) HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2018-01-18] ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2016-05-21] ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{A229B62A-8C6E-4588-8B12-BED435B7CF9C}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{B841D1F0-52EC-4F8E-AF11-60C6ABF3D201}: [DhcpNameServer] 219.76.98.66 218.102.52.81 Internet Explorer: ================== HKU\S-1-5-21-859187355-2626154896-303692081-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://us.yahoo.com/ HKU\S-1-5-21-859187355-2626154896-303692081-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/zh-hk/?ocid=iehp SearchScopes: HKU\S-1-5-21-859187355-2626154896-303692081-1000 -> DefaultScope {0EE7F8EA-A3E0-45E8-9301-FA23CBAE085E} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} SearchScopes: HKU\S-1-5-21-859187355-2626154896-303692081-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-859187355-2626154896-303692081-1000 -> {0EE7F8EA-A3E0-45E8-9301-FA23CBAE085E} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-05-20] (Oracle Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-20] (Oracle Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-20] (Oracle Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-20] (Oracle Corporation) FireFox: ======== FF DefaultProfile: uklrygk3.default FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uklrygk3.default [2018-01-19] FF Homepage: Mozilla\Firefox\Profiles\uklrygk3.default -> google.com FF Extension: (Disable JavaScript Shared Memory) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\uklrygk3.default\features\{d404695e-d501-4d58-b02c-12bfb5393d2c}\disable-js-shared-memory@mozilla.org.xpi [2018-01-19] [Legacy] FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Extension: (ESET Smart Security Extension) - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2016-05-20] [Legacy] [not signed] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_242.dll [2016-05-20] () FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-20] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-20] (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-20] () FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-20] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-20] (Oracle Corporation) FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @qq.com/npchrome -> C:\Program Files (x86)\Common Files\Tencent\Npchrome\npchrome.dll [2016-05-20] (Tencent) FF Plugin-x32: @qq.com/npqscall -> C:\Program Files (x86)\Common Files\Tencent\NPQSCALL\npqscall.dll [2016-05-20] (Tencent) FF Plugin-x32: @qq.com/TXSSO -> C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.2.1\Bin\npSSOAxCtrlForPTLogin.dll [2013-04-08] (Tencent) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.) Chrome: ======= CHR StartupUrls: Default -> "hxxps://www.google.com.hk/" CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2018-01-19] CHR Extension: (Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13] CHR Extension: (Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13] CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-20] CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-20] CHR Extension: (Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13] CHR Extension: (IndoXXI Companion) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggmhbeannpfkiafgkfobkanlpaccfdki [2017-10-20] CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-20] CHR Extension: (Chrono Download Manager) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\mciiogijehkdemklbdcbfkefimifhecn [2017-08-21] CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23] CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-20] CHR Extension: (Chrome Media Router) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-11] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [1810120 2018-01-18] () R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-03-17] (Apple Inc.) R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [873248 2010-02-17] (Broadcom Corporation.) R2 camfrog_update_service; C:\Program Files (x86)\Camfrog\Camfrog Video Chat\update\cf_update_service.exe [1063968 2016-12-19] (Camshare Inc.) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1343920 2014-09-30] (ESET) S2 KMSServerService; C:\Windows\kmsonboot\HEU_KMS_Service.exe [38454 2013-11-28] () [File not signed] R2 SpliCamService; C:\Program Files (x86)\SplitCam\SplitCamService.exe [321056 2017-08-21] (SplitCam Co.) S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10803440 2017-12-19] (TeamViewer GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) S2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [240344 2014-09-30] (ESET) U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [240344 2014-09-30] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-09-30] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [157432 2014-09-30] (ESET) R0 kavbootc; C:\Windows\System32\drivers\kavbootc64.sys [31848 2016-05-21] (Kingsoft Corporation) S3 RD9700; C:\Windows\System32\DRIVERS\RD9700.sys [21504 2012-05-26] (Corechip Semiconductor, Inc. Co Ltd.) R3 scvad_simple; C:\Windows\System32\drivers\SplitCamAudio.sys [23552 2017-08-11] (Windows (R) Win 7 DDK provider) R3 splitcam_hd_driver; C:\Windows\System32\DRIVERS\splitcam_hd_driver.sys [37600 2017-08-11] (Windows (R) Win 7 DDK provider) U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2018-01-19] () R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [214912 2010-01-27] (Vimicro Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) NETSVCx32: dg597 -> no filepath. ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-01-19 02:27 - 2018-01-19 02:27 - 000000000 ____D C:\FRST 2018-01-19 00:38 - 2018-01-19 00:38 - 000000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SplitCam 2018-01-19 00:32 - 2018-01-19 00:39 - 000000000 ____D C:\Users\User\AppData\Roaming\SplitCam 2018-01-19 00:28 - 2018-01-19 00:38 - 000000000 ____D C:\Program Files (x86)\SplitCam 2018-01-19 00:20 - 2018-01-19 00:20 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys 2018-01-19 00:19 - 2018-01-19 00:19 - 000000862 _____ C:\Users\Public\Desktop\RogueKiller.lnk 2018-01-19 00:19 - 2018-01-19 00:19 - 000000000 ____D C:\ProgramData\RogueKiller 2018-01-19 00:19 - 2018-01-19 00:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller 2018-01-19 00:18 - 2018-01-19 00:19 - 000000000 ____D C:\Program Files\RogueKiller 2018-01-19 00:12 - 2018-01-19 02:07 - 000000000 ____D C:\Users\User\AppData\LocalLow\Mozilla 2018-01-19 00:12 - 2018-01-19 00:12 - 000000940 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2018-01-19 00:12 - 2018-01-19 00:12 - 000000928 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2018-01-19 00:12 - 2018-01-19 00:12 - 000000000 ____D C:\Users\User\AppData\Roaming\Mozilla 2018-01-19 00:12 - 2018-01-19 00:12 - 000000000 ____D C:\Users\User\AppData\Local\Mozilla 2018-01-19 00:12 - 2018-01-19 00:12 - 000000000 ____D C:\Program Files\Mozilla Firefox 2018-01-19 00:12 - 2018-01-19 00:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-01-18 23:43 - 2018-01-18 23:46 - 000000000 ____D C:\ProgramData\AnyDesk 2018-01-18 23:43 - 2018-01-18 23:43 - 000001892 _____ C:\Users\Public\Desktop\AnyDesk.lnk 2018-01-18 23:43 - 2018-01-18 23:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnyDesk 2018-01-18 23:43 - 2018-01-18 23:43 - 000000000 ____D C:\Program Files (x86)\AnyDesk 2018-01-18 22:50 - 2018-01-18 23:38 - 000000000 ____D C:\Users\User\AppData\Roaming\AnyDesk ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-01-19 01:43 - 2009-07-14 12:45 - 000031280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2018-01-19 01:43 - 2009-07-14 12:45 - 000031280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2018-01-19 01:42 - 2009-07-14 13:13 - 000778150 _____ C:\Windows\system32\PerfStringBackup.INI 2018-01-19 01:42 - 2009-07-14 11:20 - 000000000 ____D C:\Windows\inf 2018-01-19 01:38 - 2009-07-14 13:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2018-01-19 00:11 - 2016-05-20 21:59 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2018-01-18 22:16 - 2017-06-14 22:02 - 000003350 _____ C:\Windows\System32\Tasks\ESET Windows 10 upgrade – Refresh settings 2018-01-18 22:06 - 2017-03-11 00:44 - 000000000 ____D C:\Users\User\AppData\Roaming\Camfrog 2018-01-14 18:00 - 2017-04-23 09:21 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2018-01-09 20:57 - 2016-05-20 22:57 - 000000000 ____D C:\Users\User\AppData\Roaming\Skype 2018-01-09 09:12 - 2016-05-20 22:46 - 000002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-01-09 09:12 - 2016-05-20 22:46 - 000002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-01-07 22:46 - 2017-04-23 09:21 - 000000000 ____D C:\Users\User\AppData\Roaming\TeamViewer 2017-12-26 17:01 - 2017-03-11 00:44 - 000000000 ____D C:\ProgramData\Camfrog Update 2017-12-24 03:37 - 2017-04-23 09:21 - 000000975 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk 2017-12-24 03:37 - 2017-04-23 09:21 - 000000963 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk ==================== Files in the root of some directories ======= 2016-11-03 11:01 - 2016-11-03 11:01 - 007065600 _____ () C:\Program Files (x86)\GUTD8E2.tmp 2016-05-21 18:00 - 2016-05-21 18:00 - 000000021 _____ () C:\Users\User\AppData\Roaming\fixcfg.ini Some files in TEMP: ==================== 2018-01-19 00:19 - 2016-05-20 21:46 - 001732032 _____ (Microsoft Corporation) C:\Users\User\AppData\Local\Temp\dllnt_dump.dll 2016-05-21 18:00 - 2016-05-21 17:41 - 000297296 _____ (MyDrivers.com) C:\Users\User\AppData\Local\Temp\khelper.exe 2016-05-21 18:00 - 2016-05-21 17:41 - 001204048 _____ (Kingsoft Corporation) C:\Users\User\AppData\Local\Temp\kinst.dll 2016-05-21 18:00 - 2016-05-21 17:41 - 000268624 _____ (MyDrivers.com) C:\Users\User\AppData\Local\Temp\kszzdl.dll 2016-05-21 18:00 - 2016-05-21 17:41 - 000330680 _____ (Microsoft Corporation) C:\Users\User\AppData\Local\Temp\msvcp80.dll 2016-05-21 18:00 - 2016-05-21 17:41 - 000249784 _____ (Microsoft Corporation) C:\Users\User\AppData\Local\Temp\msvcr80.dll 2017-04-01 17:03 - 2018-01-07 23:11 - 059165632 _____ (Skype Technologies S.A.) C:\Users\User\AppData\Local\Temp\SkypeSetup.exe 2017-04-01 17:01 - 2017-04-01 17:01 - 014456872 _____ (Microsoft Corporation) C:\Users\User\AppData\Local\Temp\vc_redist.x86.exe 2016-05-21 18:00 - 2016-05-21 17:41 - 000088400 _____ () C:\Users\User\AppData\Local\Temp\zlib.dll ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed C:\Windows\system32\drivers\eamonm.sys -> Access Denied <======= ATTENTION C:\Windows\system32\drivers\edevmon.sys -> Access Denied <======= ATTENTION C:\Windows\system32\drivers\ehdrv.sys -> Access Denied <======= ATTENTION C:\Windows\system32\drivers\epfwwfpr.sys -> Access Denied <======= ATTENTION LastRegBack: 2018-01-19 02:05 ==================== End of FRST.txt ============================ -------------------------------- Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17.01.2018 01 Ran by User (19-01-2018 02:29:54) Running from D:\Users\User\Desktop Windows 7 Professional Service Pack 1 (X64) (2016-05-20 13:13:43) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-859187355-2626154896-303692081-500 - Administrator - Disabled) Guest (S-1-5-21-859187355-2626154896-303692081-501 - Limited - Disabled) User (S-1-5-21-859187355-2626154896-303692081-1000 - Administrator - Enabled) => C:\Users\User ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: ESET NOD32 Antivirus 7.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: ESET NOD32 Antivirus 7.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 21 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 21.0.0.242 - Adobe Systems Incorporated) Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated) Adobe Flash Player 21 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 21.0.0.242 - Adobe Systems Incorporated) Adobe Reader XI MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated) AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 3.7.0 - philandro Software GmbH) Apple Application Support (32-bit) (HKLM-x32\...\{05E07D23-91E9-4E70-A4CC-EF505088F967}) (Version: 5.4.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{741291DA-2B34-4D44-8FB6-58EDE21261D8}) (Version: 5.4.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{DB18F1C0-846F-46F5-A074-5B97C8AF5C8E}) (Version: 10.3.1.2 - Apple Inc.) Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.) ATI Catalyst Install Manager (HKLM\...\{E2F5EAC1-DC02-4886-C7AC-AE7340815674}) (Version: 3.0.762.0 - ATI Technologies, Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Camfrog Video Chat 6.19 (HKLM-x32\...\Camfrog) (Version: 6.19.649 - Camshare, Inc.) ccc-core-static (HKLM-x32\...\{AE2C34DE-20D1-B68D-82FD-CB60B9C5BA3D}) (Version: 2010.0113.2208.39662 - ATI) Hidden ESET NOD32 Antivirus (HKLM\...\{E9A50574-3422-45A8-8FC2-2C74408467EA}) (Version: 7.0.325.1 - ESET, spol s r. o.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden iTunes (HKLM\...\{6C01A0A7-7440-4D48-93C6-2927A1E93FE6}) (Version: 12.6.0.100 - Apple Inc.) Java 8 Update 91 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.14 - Oracle Corporation) Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation) K-Lite Codec Pack 9.4.0 (Full) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.4.0 - ) Lenovo Bluetooth with Enhanced Data Rate Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.1400 - Broadcom Corporation) Lenovo EasyCamera (HKLM-x32\...\{ADE16A9D-FBDC-4ecc-B6BD-9C31E51D0332}) (Version: 1.10.01.29.1 - Vimicro) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Mozilla Firefox 57.0.4 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0.4 (x64 en-US)) (Version: 57.0.4 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 57.0.4 - Mozilla) QQ International (HKLM-x32\...\{3CA54984-A14B-42FE-9FF1-7EA90151D725}) (Version: 1.91.1369.0 - Tencent Technology(Shenzhen) Company Limited) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6093 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30116 - Realtek Semiconductor Corp.) RogueKiller version 12.12.0.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.0.0 - Adlice Software) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) SplitCam (HKLM-x32\...\SplitCam) (Version: 7.7.4.1 - SplitCam Co) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.19.0 - Synaptics Incorporated) TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.90922 - TeamViewer) Windows Driver Package - Broadcom (BTHUSB) Bluetooth (02/25/2010 6.2.0.9419) (HKLM\...\85CE3A3657FAE5FD305B143E90E6FC89BA53001C) (Version: 02/25/2010 6.2.0.9419 - Broadcom) Windows Driver Package - Broadcom Bluetooth (01/19/2010 6.2.0.1417) (HKLM\...\7341A1B43E7FE58942EB1E820A17C18305DFBCE6) (Version: 01/19/2010 6.2.0.1417 - Broadcom) Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\3BA80AB4C7E9F8497C115C844953A3D4BEB84D21) (Version: 07/28/2009 6.2.0.9800 - Broadcom) WinRAR archiver (HKLM\...\WinRAR archiver) (Version: - ) Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version: - Yahoo! Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2014-09-30] (ESET) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-03-15] () ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-03-15] () ContextMenuHandlers2: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2014-09-30] (ESET) ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-03-15] () ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-03-15] () ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2010-01-13] (Advanced Micro Devices, Inc.) ContextMenuHandlers6: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET NOD32 Antivirus\shellExt.dll [2014-09-30] (ESET) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-03-15] () ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-03-15] () ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {26DA7A01-F82E-490A-A265-E8665B7338D8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.) Task: {358036C5-CDD7-4EF6-B6BB-4F29C79DE9D5} - System32\Tasks\ESET Windows 10 upgrade – Refresh settings => C:\Program Files\Common Files\AV\ESET NOD32 Antivirus 7.0\upgrade.exe [2017-10-30] (ESET) Task: {7CC01537-7DFF-40F4-B770-A280DADC3C37} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-20] (Google Inc.) Task: {888D79D9-B3E7-4A00-AF9E-26FF9A0CA419} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-05-20] (Google Inc.) Task: {A76D9E4D-811C-4994-BBFF-496D8849E3C8} - System32\Tasks\HEU_KMS_Service_ONSTART => C:\Windows\kmsonboot\autoact.exe [2013-11-28] (HEU CNST) Task: {BA6BDA3A-1FAC-4D99-919E-DCE183F16291} - System32\Tasks\HEU_KMS_Service_WEEKLY => C:\Windows\kmsonboot\autoact.exe [2013-11-28] (HEU CNST) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2018-01-18 23:43 - 2018-01-18 22:50 - 001810120 _____ () C:\Program Files (x86)\AnyDesk\AnyDesk.exe 2017-03-16 16:08 - 2017-03-16 16:08 - 001354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2017-03-16 16:08 - 2017-03-16 16:08 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-05-20 21:31 - 2010-03-15 11:28 - 000166400 _____ () C:\Program Files\WinRAR\rarext.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 001354040 _____ () C:\Program Files\iTunes\libxml2.dll 2017-03-27 12:20 - 2017-03-27 12:20 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll 2010-02-17 23:26 - 2010-02-17 23:26 - 000173344 _____ () C:\Program Files\Lenovo\Bluetooth Software\btkeyind.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 002088960 _____ () C:\Program Files (x86)\SplitCam\opencv_core246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 001905664 _____ () C:\Program Files (x86)\SplitCam\opencv_imgproc246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 002092544 _____ () C:\Program Files (x86)\SplitCam\opencv_highgui246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 000667648 _____ () C:\Program Files (x86)\SplitCam\opencv_objdetect246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 000379904 _____ () C:\Program Files (x86)\SplitCam\opencv_video246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 000797696 _____ () C:\Program Files (x86)\SplitCam\opencv_calib3d246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 000493568 _____ () C:\Program Files (x86)\SplitCam\opencv_flann246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 000732672 _____ () C:\Program Files (x86)\SplitCam\opencv_features2d246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 001236992 _____ () C:\Program Files (x86)\SplitCam\opencv_legacy246.dll 2017-08-11 16:27 - 2017-08-11 16:27 - 000514048 _____ () C:\Program Files (x86)\SplitCam\opencv_ml246.dll 2016-05-20 22:05 - 2012-10-25 02:00 - 003501056 _____ () C:\Program Files (x86)\K-Lite Codec Pack\Filters\ffdshow\ffdshow.ax 2017-08-21 12:03 - 2017-08-21 12:03 - 000179232 _____ () C:\Program Files (x86)\SplitCam\AudioGrabber.ax ==================== Alternate Data Streams (Whitelisted) ========= ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 10:34 - 2009-06-11 05:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-859187355-2626154896-303692081-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: AMD External Events Utility => 2 MSCONFIG\Services: TeamViewer => 2 MSCONFIG\startupreg: Energy Management => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe MSCONFIG\startupreg: EnergyUtility => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe MSCONFIG\startupreg: RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{B9AC4A1B-06C3-40D5-8D04-8AC0B0AED259}] => (Allow) LPort=1688 FirewallRules: [{019A6368-80B8-48D8-86C1-259A7714F6E3}] => (Allow) LPort=1688 FirewallRules: [{9DAB13FF-16BD-4F23-8667-DFED93508404}] => (Allow) C:\Windows\kmsonboot\HEU_KMS_Service.exe FirewallRules: [{1CF50D46-2DF2-4A83-BB04-3413C78B13AA}] => (Allow) C:\Windows\kmsonboot\HEU_KMS_Service.exe FirewallRules: [{E3ABE9D9-E2C6-466C-8CCF-64BAF95AE100}] => (Allow) C:\Windows\system32\sppsvc.exe FirewallRules: [{19701D8B-690B-434C-86F9-DDAC4359DD37}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{9603F196-358C-461F-96F4-6062903766AC}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{0C8028DE-5744-4B48-9556-EA7E5B0F32F9}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe FirewallRules: [{AEA364D7-C7A1-414A-9AED-DB8F8E62B3D9}] => (Allow) C:\Program Files (x86)\Tencent\QQIntl\Bin\QQ.exe FirewallRules: [{E439517B-D1A8-4656-A069-D51AA06DFB69}] => (Allow) C:\Program Files (x86)\Tencent\QQIntl\Bin\QQ.exe FirewallRules: [{2DFDD66E-587A-4FB4-AF4D-BD022E63ABD7}] => (Allow) C:\Program Files (x86)\Common Files\Tencent\QQDownload\119\Tencentdl.exe FirewallRules: [{065B2555-C998-409F-8960-D4DCC5265157}] => (Allow) C:\Program Files (x86)\Common Files\Tencent\QQDownload\119\Tencentdl.exe FirewallRules: [{2C4F649D-7C74-4D88-AA57-5D7AA2C72B7C}] => (Allow) C:\Program Files (x86)\MyDrivers\DriverGenius\xlmodule\download\minithunderplatform.exe FirewallRules: [{1F489D81-DC3D-4F3C-A533-418FF700F464}] => (Allow) C:\Program Files (x86)\MyDrivers\DriverGenius\xlmodule\download\minithunderplatform.exe FirewallRules: [TCP Query User{D907E9C6-30AF-4193-94AE-71E2D4D25EA8}C:\program files (x86)\camfrog\camfrog video chat\camfrog video chat.exe] => (Block) C:\program files (x86)\camfrog\camfrog video chat\camfrog video chat.exe FirewallRules: [UDP Query User{96231707-EB10-42B5-BEB7-F9384B46F1FA}C:\program files (x86)\camfrog\camfrog video chat\camfrog video chat.exe] => (Block) C:\program files (x86)\camfrog\camfrog video chat\camfrog video chat.exe FirewallRules: [{7E87FB37-98D0-4F4C-843F-308CCB83701B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{62E7F7C2-D02E-483B-9E61-DBBEE110B7A2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{C34C8F84-8581-4512-A3B6-E9E2BCAC9D97}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{F4B6FE27-EA9F-4298-A97E-76BA443026E1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{E13B76D3-5C7E-4908-B358-959A4376C297}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{EB6DBF8B-42D6-4AFC-ADF1-D8E3C6DBA8FE}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{64FBD319-95B2-435A-8401-AA8CA37314EC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{170FF740-1A48-4766-8176-90C83702F03A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{DF901147-834B-46D0-AAAA-973D82163281}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{97BC348B-50CA-4F6E-9742-B96B655A6330}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{5CAAD798-A3CB-4116-B4BD-063CEE3A4499}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{1A78C8D5-3C0D-48B4-B38A-6B6DB1BDFDA5}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{A910F8B4-553D-4859-B6F2-F049621CDBD4}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{6EF22FE5-FAF3-40B2-88B4-A51B59020C61}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{AA3F3FC0-11C5-445D-B0F5-381C7EA62CA3}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{45CC30C7-D629-40CC-ACAD-97E21718D31E}] => (Allow) D:\Users\User\Downloads\AnyDesk.exe FirewallRules: [{69CB1B3B-0BF6-4B12-933C-63DD268B1068}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{3F4575FC-84C5-4511-B7AD-E546BD78DABA}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe FirewallRules: [{D73A0569-F754-432A-B369-D7C0718E4CBC}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{70210710-BCAE-4812-8DAB-FAE8444D49B9}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{527557D8-BBE7-45CB-B516-2143E00FE7B0}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{72ADE0AB-8EAA-4E15-94F9-BB6A0FC749BF}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{6F8D0FFE-02E8-46CC-B325-0F78859ABAA3}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe FirewallRules: [{C42DDF04-C97F-4CC9-9FFC-95975E3BC67E}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe ==================== Restore Points ========================= 09-12-2017 19:02:48 Scheduled Checkpoint 19-12-2017 16:29:34 Scheduled Checkpoint 26-12-2017 19:50:17 Scheduled Checkpoint 03-01-2018 00:00:04 Scheduled Checkpoint 19-01-2018 00:06:32 Removed Energy Management 19-01-2018 00:29:38 Device Driver Package Install: SplitCam Sound, video and game controllers ==================== Faulty Device Manager Devices ============= Name: Lexmark X422 Description: Lexmark X422 Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: Lexmark Service: usbscan Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/19/2018 01:39:38 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/19/2018 12:31:22 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:31:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:31:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:31:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:31:21 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:29:55 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object. Details: AddLegacyDriverFiles: Unable to back up image of binary LHDmgr. System Error: The system cannot find the file specified. . Error: (01/19/2018 12:29:19 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:29:19 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . Error: (01/19/2018 12:29:19 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: ) Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file. . System errors: ============= Error: (01/19/2018 01:38:33 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (01/19/2018 01:38:11 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error: The system cannot find the file specified. Error: (01/19/2018 12:03:21 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (01/19/2018 12:03:04 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error: The system cannot find the file specified. Error: (01/18/2018 11:38:55 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 40. The internal error state is 252. Error: (01/18/2018 11:38:55 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY) Description: The following fatal alert was generated: 40. The internal error state is 252. Error: (01/18/2018 10:05:46 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (01/18/2018 10:05:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error: The system cannot find the file specified. Error: (01/17/2018 09:33:31 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: The following boot-start or system-start driver(s) failed to load: cdrom Error: (01/17/2018 09:33:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Cyberlink RichVideo Service(CRVS) service failed to start due to the following error: The system cannot find the file specified. CodeIntegrity: =================================== Date: 2018-01-19 02:16:54.127 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-19 02:16:42.754 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-18 23:05:30.518 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-17 07:23:34.162 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-17 02:02:54.624 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-17 01:00:23.316 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-17 00:59:30.816 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-17 00:51:04.323 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-17 00:47:06.223 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. Date: 2018-01-17 00:43:46.117 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: AMD Athlon(tm) II Neo K125 Processor Percentage of memory in use: 51% Total physical RAM: 3838.17 MB Available physical RAM: 1873.44 MB Total Virtual: 7674.52 MB Available Virtual: 5253.68 MB ==================== Drives ================================ Drive c: (Win7) (Fixed) (Total:150.01 GB) (Free:112.58 GB) NTFS ==>[drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:82.87 GB) (Free:82.13 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows XP) (Size: 232.9 GB) (Disk ID: 000885B3) Partition 1: (Active) - (Size=150 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=82.9 GB) - (Type=OF Extended) ==================== End of Addition.txt ============================
  9. Broni, I can see in the device manager the said device must have auto updated itself and now its working. Thanks for your time.
  10. Yes , updates working now! Thanks a lot Broni! When I look in the device manager there is unknown device showing with no driver. How do I fix that please?
  11. Ok finished here is the log: Tweaking.com - Windows Repair 2018 (v4.0.12) -------------------------------------------------------------------------------- System Variables -------------------------------------------------------------------------------- OS: Windows 10 Home Single Language OS Architecture: 64-bit OS Version: 10.0.16299.192 OS Service Pack: Computer Name: JESTERPC Windows Drive: C:\ Windows Path: C:\WINDOWS Program Files: C:\Program Files Program Files (x86): C:\Program Files (x86) Current Profile: C:\Users\ihya Current Profile SID: S-1-5-21-4006158168-3018101353-126307802-1001 Current Profile Classes: S-1-5-21-4006158168-3018101353-126307802-1001_Classes Profiles Location: C:\Users Profiles Location 2: C:\WINDOWS\ServiceProfiles Local Settings AppData: C:\Users\ihya\AppData\Local -------------------------------------------------------------------------------- System Information -------------------------------------------------------------------------------- System Up Time: 0 Days 00:51:26 Process Count: 130 Commit Total: 2.09 GB Commit Limit: 4.30 GB Commit Peak: 3.73 GB Handle Count: 42408 Kernel Total: 514.64 MB Kernel Paged: 283.61 MB Kernel Non Paged: 231.04 MB System Cache: 2.07 GB Thread Count: 1271 -------------------------------------------------------------------------------- Memory Before Cleaning with CleanMem -------------------------------------------------------------------------------- Memory Total: 3.91 GB Memory Used: 1.80 GB(46.1533%) Memory Avail.: 2.10 GB -------------------------------------------------------------------------------- Cleaning Memory Before Starting Repairs... Memory After Cleaning with CleanMem -------------------------------------------------------------------------------- Memory Total: 3.91 GB Memory Used: 1.53 GB(39.0607%) Memory Avail.: 2.38 GB -------------------------------------------------------------------------------- Starting Repairs... Started at (1/17/2018 1:09:46 PM) Setting Any Missing 'InstallDate' From Uninstall Sections Before Running Repair... Total Missing 'InstallDate' Fixed: 52 01 - Reset Registry Permissions Restore Windows 7/8/10 Default Registry Permissions Start (1/17/2018 1:09:53 PM) Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\hku.7z Done, 0.48 seconds. Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\hklm.7z Done, 7.9 seconds. Running Repair Under System Account Done (1/17/2018 1:12:19 PM) 02 - Reset File Permissions Restore Windows 7/8/10 Default File Permissions Start (1/17/2018 1:12:19 PM) Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\default.7z Done, 0.25 seconds. Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\profile.7z Done, 0.36 seconds. Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\program_files.7z Done, 0.45 seconds. Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\program_files_x86.7z Done, 0.52 seconds. Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\programdata.7z Done, 0.3 seconds. Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\windows.7z Done, 1.75 seconds. Running Repair Under System Account Done (1/17/2018 1:27:22 PM) 03 - Reset Service Permissions Start (1/17/2018 1:27:22 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:28:05 PM) 04 - Register System Files Start (1/17/2018 1:28:05 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:30:02 PM) 05 - Repair WMI Start (1/17/2018 1:30:02 PM) Starting Security Center So We Can Export The Security Info. Exporting Antivirus Info... Windows Defender Exported. Exporting AntiSpyware Info... Windows Defender Exported. Exporting 3rd Party Firewall Info... No Firewall Products Reported. Running Repair Under Current User Account Done (1/17/2018 1:37:50 PM) 06 - Repair Windows Firewall Start (1/17/2018 1:37:50 PM) Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z Done, 0.23 seconds. Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:38:03 PM) 07 - Repair Internet Explorer Start (1/17/2018 1:38:03 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:38:25 PM) 08 - Repair MDAC/MS Jet Start (1/17/2018 1:38:25 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:38:36 PM) 09 - Repair Hosts File Start (1/17/2018 1:38:36 PM) Running Repair Under System Account Done (1/17/2018 1:38:38 PM) 10 - Remove Policies Set By Infections Start (1/17/2018 1:38:38 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:38:41 PM) 11 - Repair Start Menu Icons Removed By Infections Start (1/17/2018 1:38:41 PM) Running Repair Under System Account Done (1/17/2018 1:38:42 PM) 12 - Repair Icons Start (1/17/2018 1:38:42 PM) Running Repair Under Current User Account Done (1/17/2018 1:38:52 PM) 13 - Repair Network Start (1/17/2018 1:38:52 PM) Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z Done, 0.21 seconds. Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:39:12 PM) 14 - Remove Temp Files Start (1/17/2018 1:39:12 PM) Running Repair Under System Account Done (1/17/2018 1:39:13 PM) 15 - Repair Proxy Settings Start (1/17/2018 1:39:14 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:39:16 PM) 16 - Repair Windows Updates Start (1/17/2018 1:39:16 PM) Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z Done, 0.23 seconds. Running Repair Under Current User Account Running Repair Under System Account Setting Windows Updates Files That Are In Use To Be Removed At Next Boot. Done (1/17/2018 1:39:51 PM) 17 - Repair CD/DVD Missing/Not Working Start (1/17/2018 1:39:51 PM) iTunes or GEARAspiWDM.sys not found, not applying UpperFilters iTunes Reg Key Done (1/17/2018 1:39:51 PM) 18 - Repair Volume Shadow Copy Service Start (1/17/2018 1:39:51 PM) Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z Done, 0.22 seconds. Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:31 PM) 19 - Repair Windows Sidebar/Gadgets Start (1/17/2018 1:40:31 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:33 PM) 20 - Repair MSI (Windows Installer) Start (1/17/2018 1:40:33 PM) Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z Done, 0.19 seconds. Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:45 PM) 21 - Repair Windows Snipping Tool Start (1/17/2018 1:40:45 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:47 PM) 22.01 - Repair bat Association Start (1/17/2018 1:40:47 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:49 PM) 22.02 - Repair cmd Association Start (1/17/2018 1:40:49 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:52 PM) 22.03 - Repair com Association Start (1/17/2018 1:40:52 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:54 PM) 22.04 - Repair Directory Association Start (1/17/2018 1:40:54 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:56 PM) 22.05 - Repair Drive Association Start (1/17/2018 1:40:56 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:40:59 PM) 22.06 - Repair exe Association Start (1/17/2018 1:40:59 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:01 PM) 22.07 - Repair Folder Association Start (1/17/2018 1:41:01 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:03 PM) 22.08 - Repair inf Association Start (1/17/2018 1:41:03 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:06 PM) 22.09 - Repair lnk (Shortcuts) Association Start (1/17/2018 1:41:06 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:08 PM) 22.10 - Repair msc Association Start (1/17/2018 1:41:08 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:10 PM) 22.11 - Repair reg Association Start (1/17/2018 1:41:10 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:12 PM) 22.12 - Repair scr Association Start (1/17/2018 1:41:12 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:15 PM) 23 - Repair Windows Safe Mode Start (1/17/2018 1:41:15 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:17 PM) 24 - Repair Print Spooler Start (1/17/2018 1:41:17 PM) Decompressing & Updating Windows Permission File C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\permissions\10\services.7z Done, 0.19 seconds. Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 1:41:31 PM) 25 - Restore Important Windows Services Skipping Repair. This repair is currently being updated to support the Windows 10 Fall Update 26 - Set Windows Services To Default Startup Skipping Repair. This repair is currently being updated to support the Windows 10 Fall Update 27.01 - Repair Windows 8/10 App Store Skipping Repair. This repair is currently disabled for this version of Windows due to the constant changes to the app store. 28 - Repair Windows 8/10 Component Store Start (1/17/2018 1:41:31 PM) Running Repair Under Current User Account Done (1/17/2018 2:23:49 PM) 29 - Restore Windows 8/10 COM+ Unmarshalers Start (1/17/2018 2:23:49 PM) Running Repair Under System Account [X] -----Job Complete----- Items Done: 1 Done (1/17/2018 2:23:52 PM) 30 - Repair Windows 'New' Submenu Start (1/17/2018 2:23:52 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 2:23:55 PM) 31 - Restore UAC (User Account Control) Settings Start (1/17/2018 2:23:55 PM) Running Repair Under Current User Account Running Repair Under System Account Done (1/17/2018 2:23:57 PM) 32 - Repair Performance Counters Start (1/17/2018 2:23:57 PM) Running Repair Under Current User Account Done (1/17/2018 2:24:06 PM) Cleaning up empty logs... All Selected Repairs Done. Done at (1/17/2018 2:24:06 PM) Total Repair Time: 01:14:23 ...YOU MUST RESTART YOUR SYSTEM...
  12. I'm back in Windows 10! I'm still not able to get Windows updates. :( I get this message: We couldn't connect to the update service. We'll try again later, or you can check now. If it still doesn't work, make sure you're connected to the Internet. I'm connected thru remote so I know its connected to the internet. :D
  13. Well I managed to fix it. I went into network adapters and edit the IPv4 DNS with google 8.8.8.8 and alt 8.8.4.4. Now Im able to get the Win 10 upgrade downloading.
  14. Not sure why it posted 3 times sorry. That error code says to fix the host file. I'm logged in as administrator but I'm not able to edit the file.
  15. Won't let me upgrade. I get error code: Microsoft error code 0x80072ee7
×