Jump to content

All Activity

This stream auto-updates     

  1. Past hour
  2. Ski52

    Shutdown

    I suppose when the Government starts back up, all these people will get back pay for not working??? For those of us who have been 'laid off' in the past, and went back to work for the same employer, did you ever receive any type of compensation for the time you didn't work? If on the other hand they worked without pay, by all means they need to get back pay, maybe even a little extra incentive added.
  3. Ski52

    Famous People A to Z

    Amelia Earhart
  4. No Desktop Log folder. It created a log folder in it's own folder. There are also 2 chkdsk files in the folder. Which files do you want? The version I have is V4.4.0.1. The GUI is different from your instructions. Also, assuming the USB problem is fixed, should I run the program again when I turn on the 2 TB expansion box and introduce untested files back into the system?
  5. Today
  6. Broken Club

    Famous People A to Z

    Matthew Paige Damon was born on October 8, 1970, in Boston, Massachusetts ..
  7. Broken Club

    Jan. 9 - Jan. 16

    post # 1 Photo # 1
  8. frazzm737

    Famous People A to Z

    James Fenimore Cooper
  9. Broni

    Famous People A to Z

    Johann Sebastian Bach
  10. frazzm737

    Famous People A to Z

    For this game, we will use last names. I will begin with a famous person whose last name begin with the letter A. The next member will post the name of a famous person whose last name begins with the letter B and so on through the alphabet. You must wait til another member has posted before you can post a second name. John Adams
  11. frazzm737

    Our Games

    Tonight we are going to try a new game topic. Broni has suggested it after seeing its success on another forum. Each game suggested will be explained as we go along. These games are only for fun, no prizes. I will start one game tonight. Any member may start another game at any time. You will soon get the hang of it.
  12. Broni

    Jan. 9 - Jan. 16

    #12
  13. Broni

    Wondershare Helper Compact

    Welcome aboard All you have there is just one registry leftover. No big deal but we can remove it with the following step... Download attached fixlist.txt file and save it to the Desktop. NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST(FRST64) and press the Fix button just once and wait. The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply. fixlist.txt
  14. frazzm737

    Jan. 9 - Jan. 16

    Time to vote! I like Post #9, Photo#2. I'm still hoping this little guy survived.
  15. We both understand this is Vista, rather old operating system and the computer itself must be pretty old, so we can't expect any miracles. Download attached fixlist.txt file and save it to the Desktop. NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST(FRST64) and press the Fix button just once and wait. The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply. fixlist.txt
  16. KQuist95

    Wondershare Helper Compact

    Users shortcut scan result (x64) Version: 14.01.2019 01 Ran by Kurt (15-01-2019 19:16:47) Running from C:\Users\Kurt\Desktop\PC Management Boot Mode: Normal ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iRacing\Start iRacing Service (background task).lnk -> C:\Program Files (x86)\iRacing\Start_iRacingService.bat () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\01 - File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\03 - Documents.lnk -> C:\Users\Kurt\Documents () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\04 - Downloads.lnk -> C:\Users\Kurt\Downloads () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\05 - Music.lnk -> C:\Users\Kurt\Music () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\06 - Pictures.lnk -> C:\Users\Kurt\Pictures () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\07 - Videos.lnk -> C:\Users\Kurt\Videos () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\08 - Homegroup.lnk -> Microsoft.Windows.Homegroup Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\09 - Network.lnk -> Microsoft.Windows.Network Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu Places\10 - UserProfile.lnk -> C:\Users\Kurt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\TP Updater.lnk -> C:\Program Files (x86)\Rhinode LLC\Trading Paints\TP Updater.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Trading Paints.lnk -> C:\Program Files (x86)\Rhinode LLC\Trading Paints\Trading Paints.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Media Suite Essentials.lnk -> C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Media Suite\CMSLauncher.exe (CyberLink Corp.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk -> C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Keyboard Layout Creator 1.4.lnk -> C:\Program Files (x86)\Microsoft Keyboard Layout Creator 1.4\MSKLC.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk -> C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (dotPDN LLC) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk -> C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe (No File) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\MSPUB.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk -> C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe (TeamSpeak Systems GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 13.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vJoy\Configure vJoy.lnk -> C:\Program Files\vJoy\x64\vJoyConf.exe (Shaul Eizikovich) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vJoy\Monitor vJoy.lnk -> C:\Program Files\vJoy\x64\JoyMonitor.exe (Shaul Eizikovich) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vJoy\Uninstall vJoy.lnk -> C:\Program Files\vJoy\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vJoy\vJoy Device List.lnk -> C:\Program Files\vJoy\x64\vJoyList.exe (Shaul Eizikovich) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vJoy\vJoy Feeder (Demo).lnk -> C:\Program Files\vJoy\x64\vJoyFeeder.exe (Shaul Eizikovich) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk -> C:\Program Files (x86)\VideoLAN\VLC\Documentation.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk -> C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk -> C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thrustmaster FFB Racing wheel\Control Panel.lnk -> C:\Program Files\Thrustmaster\FFB Racing wheel\drivers\tmJoycpl.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thrustmaster FFB Racing wheel\Firmware Update.lnk -> C:\Program Files\Guillemot\tmfwupdater\tmStartFUW.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Digital Race Engineer\Uninstall The Digital Race Engineer.lnk -> C:\Apps\The Digital Race Engineer\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Create USB Recovery.lnk -> C:\Windows\System32\RecoveryDrive.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk -> C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.766\SSScheduler.exe (McAfee, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos\Sophos Virus Removal Tool\Sophos Virus Removal Tool.lnk -> C:\Windows\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe (Macrovision Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Sleep\PC Sleep.lnk -> C:\Program Files (x86)\PC Sleep\PC Sleep.exe (www.pc-sleep.com) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio\OBS Studio (64bit).lnk -> C:\Program Files (x86)\obs-studio\bin\64bit\obs64.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio\Uninstall.lnk -> C:\Program Files (x86)\obs-studio\uninstall.exe (obsproject.com) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\GeForce Experience.lnk -> C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision Photo Viewer.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe (NVIDIA Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Language Preferences.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Skype for Business Recording Manager.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Telemetry Dashboard for Office.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\msotd.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Telemetry Log for Office.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech\Logitech Webcam Software.lnk -> C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\HelpMain\launchershortcut.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.2\LibreOffice Base.lnk -> C:\Program Files (x86)\LibreOffice 5\program\sbase.exe (The Document Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.2\LibreOffice Calc.lnk -> C:\Program Files (x86)\LibreOffice 5\program\scalc.exe (The Document Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.2\LibreOffice Draw.lnk -> C:\Program Files (x86)\LibreOffice 5\program\sdraw.exe (The Document Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.2\LibreOffice Impress.lnk -> C:\Program Files (x86)\LibreOffice 5\program\simpress.exe (The Document Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.2\LibreOffice Math.lnk -> C:\Program Files (x86)\LibreOffice 5\program\smath.exe (The Document Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.2\LibreOffice Writer.lnk -> C:\Program Files (x86)\LibreOffice 5\program\swriter.exe (The Document Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.2\LibreOffice.lnk -> C:\Program Files (x86)\LibreOffice 5\program\soffice.exe (The Document Foundation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Joel Real Timing\JRT Overlays.lnk -> C:\Joel Real Timing\Electron-Overlays\electron-overlays.exe (GitHub, Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Joel Real Timing\JRT Server.lnk -> C:\Joel Real Timing\Timing.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Joel Real Timing\Uninstall Joel Real Timing.lnk -> C:\Joel Real Timing\unins000.exe () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\javacpl.exe (Oracle Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iRacing\iRacing.lnk -> C:\Program Files (x86)\iRacing\iRacingSim64DX11.exe (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Intel(R) Rapid Storage Technology.lnk -> C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorUI.exe (Intel Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Intel(R) Ready Mode Technology\Intel(R) Ready Mode Technology.lnk -> C:\Program Files\Intel\Intel(R) Ready Mode Technology\IRMTModernUI.exe (Intel Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo\Gyazo GIF.lnk -> C:\Program Files (x86)\Gyazo\GyazoGIF.exe (Nota Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo\Gyazo.lnk -> C:\Program Files (x86)\Gyazo\Gyazowin.exe (Nota Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Audio\Dell Audio.lnk -> C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Dell Digital Delivery.lnk -> C:\Program Files (x86)\Dell Digital Delivery\DeliveryTray.exe (Dell Products, LP) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Dell Product Registration.lnk -> C:\Program Files\Dell\Dell Product Registration\ProductRegistration.exe (Dell) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Dell Update.lnk -> C:\Program Files (x86)\Dell Update\DellUpTray.exe (Dell Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\Dell Help & Support\Dell Help & Support.lnk -> C:\Program Files\Dell\Dell Help & Support\Dell Help & Support.exe (Dell Inc.) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk -> C:\Windows\SysWOW64\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\RecoveryDrive.lnk -> C:\Windows\System32\RecoveryDrive.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Defender Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -> C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Quick Assist.lnk -> C:\Windows\System32\quickassist.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk -> C:\Windows\System32\psr.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk -> C:\Program Files\7-Zip\7zFM.exe (Igor Pavlov) Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk -> C:\Program Files\7-Zip\7-zip.chm () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Oculus\Oculus Support.lnk -> C:\Program Files\Oculus\Oculus.ico () Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Oculus\Oculus.lnk -> C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\Kurt\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\Videos\Documents - Shortcut.lnk -> C:\Users\Kurt\Documents () Shortcut: C:\Users\Kurt\Links\Desktop.lnk -> C:\Users\Kurt\Desktop () Shortcut: C:\Users\Kurt\Links\Downloads.lnk -> C:\Users\Kurt\Downloads () Shortcut: C:\Users\Kurt\Documents\Borderless Gaming.lnk -> C:\Program Files (x86)\Borderless Gaming\BorderlessGaming.exe (No File) Shortcut: C:\Users\Kurt\Documents\Documents - Shortcut.lnk -> C:\Users\Kurt\Documents () Shortcut: C:\Users\Kurt\Documents\Downloads - Shortcut.lnk -> C:\Users\Kurt\Downloads () Shortcut: C:\Users\Kurt\Documents\GeForce Experience.lnk -> C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (NVIDIA Corporation) Shortcut: C:\Users\Kurt\Documents\Logitech Webcam Software .lnk -> C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\HelpMain\launchershortcut.exe () Shortcut: C:\Users\Kurt\Documents\Madden NFL 19.lnk -> C:\Program Files (x86)\Origin Games\Madden NFL 19\Madden19.exe (No File) Shortcut: C:\Users\Kurt\Documents\MSI Afterburner.lnk -> C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe () Shortcut: C:\Users\Kurt\Documents\Origin.lnk -> C:\Program Files (x86)\Origin\Origin.exe (No File) Shortcut: C:\Users\Kurt\Documents\Soda Player.lnk -> C:\Users\Kurt\AppData\Local\sodaplayer\Soda Player.exe (Soda Player) Shortcut: C:\Users\Kurt\Documents\TeamViewer 13.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) Shortcut: C:\Users\Kurt\Documents\THE GUN SHOW EPISODES\CHROME.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\Kurt\Documents\BROADCAST\OBS Studio.lnk -> C:\Program Files (x86)\obs-studio\bin\64bit\obs64.exe () Shortcut: C:\Users\Kurt\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\Kurt\Desktop\iRacing.lnk -> C:\Program Files (x86)\iRacing\iRacingSim64DX11.exe (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) Shortcut: C:\Users\Kurt\Desktop\OculusDebugTool - Shortcut.lnk -> C:\Users\Kurt\Documents\oculus-diagnostics\OculusDebugTool.exe (Oculus VR) Shortcut: C:\Users\Kurt\Desktop\Settings.lnk -> Tile and icon assets Shortcut: C:\Users\Kurt\Desktop\Soda Player.lnk -> C:\Users\Kurt\AppData\Local\sodaplayer\Soda Player.exe (Soda Player) Shortcut: C:\Users\Kurt\Desktop\Spotify.lnk -> C:\Users\Kurt\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) Shortcut: C:\Users\Kurt\Desktop\PC Management\Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes) Shortcut: C:\Users\Kurt\Desktop\PC Management\pc decrapifier-3.0.1 - Shortcut.lnk -> C:\Users\Kurt\Documents\pc-decrapifier-3.0.1.exe () Shortcut: C:\Users\Kurt\Desktop\PC Management\Sophos Virus Removal Tool.lnk -> C:\Windows\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe (Macrovision Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Word\rough%20draft306544581255249959\rough%20draft.docx.lnk -> C:\Users\Kurt\Desktop\rough draft.docx (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk -> C:\Users\Kurt\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk -> C:\Users\Kurt\Documents () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostyModManager.lnk -> C:\Users\Kurt\Desktop\mod\FrostyModManager.exe (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iRacing.lnk -> C:\Users\Kurt\Documents\iRacing () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iRacingBrowserApps.lnk -> C:\Users\Kurt\Desktop\iRacingBrowserApps (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iRacingSim64DX11.lnk -> C:\Program Files (x86)\iRacing\iRacingSim64DX11.exe (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\irFFB.lnk -> C:\Users\Kurt\Documents\irFFB.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\latemodel.lnk -> C:\Users\Kurt\Documents\iRacing\setups\latemodel () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\McAfee WebAdvisor.lnk -> C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Motion_Cockpit_View_Activator.lnk -> C:\Users\Kurt\Documents\iRacing\Motion_Cockpit_View_Activator.exe (Stéphane TURPIN) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OCULUS MIRROR.lnk -> C:\Program Files\Oculus\Support\oculus-diagnostics\OculusMirror.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OculusDebugTool.lnk -> C:\Users\Kurt\Documents\oculus-diagnostics\OculusDebugTool.exe (Oculus VR) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\Kurt\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\pc decrapifier-3.0.1 - Shortcut.lnk -> C:\Users\Kurt\Documents\pc-decrapifier-3.0.1.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RAGE Multiplayer.lnk -> C:\RAGEMP\updater.exe (RAGE Multiplayer) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recycle Bin.lnk -> [LFx@_dP/N1SPSU(Ly9K-e)::{645FF040-5081-101B-9F08-00AA002F954E}] Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\skmodified tour.lnk -> C:\Users\Kurt\Documents\iRacing\setups\skmodified tour () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\skmodified.lnk -> C:\Users\Kurt\Documents\iRacing\setups\skmodified () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk -> C:\Users\Kurt\AppData\Roaming\Spotify\Spotify.exe (Spotify Ltd) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\stockcars2 nwcamaro2014.lnk -> C:\Users\Kurt\Documents\iRacing\setups\stockcars2 nwcamaro2014 () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TRJ12_USB_ADAPTER_Calibration_Tool(V1.lnk -> C:\Users\Kurt\Documents\T.RJ12_USB_ADAPTER_Calibration_Tool(V1.05).exe (Thrustmaster (R)) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\trucks silverado2015.lnk -> C:\Users\Kurt\Documents\iRacing\setups\trucks silverado2015 () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.chm () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Virtual Racing School (VRS)\Virtual Racing School (VRS) - Telemetry Logger.lnk -> C:\Users\Kurt\VirtualRacingSchool\VRS-TelemetryLogger.exe (Smarty Co.) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z\TechPowerUp GPU-Z.lnk -> C:\Program Files (x86)\GPU-Z\GPU-Z.exe (techPowerUp (www.techpowerup.com)) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z\Uninstall.lnk -> C:\Program Files (x86)\GPU-Z\uninstall.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Steam.lnk -> C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soda Player\Soda Player.lnk -> C:\Users\Kurt\AppData\Local\sodaplayer\Soda Player.exe (Soda Player) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SLR VR Application\SLR VR Application.lnk -> C:\Users\Kurt\AppData\Local\SLR VR Application\SLR.exe (VRS Technologies) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SLR VR Application\Uninstall.lnk -> C:\Users\Kurt\AppData\Local\SLR VR Application\Uninstall.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\ReadMe.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\Doc\ReadMe.pdf () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\RivaTuner Statistics Server.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\Uninstall.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\Uninstall.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\SDK\RivaTuner Statistics Server localization reference.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\SDK\Doc\Localization reference.pdf () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\SDK\RivaTuner Statistics Server skin format reference.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\SDK\Doc\USF skin format reference.pdf () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server\SDK\Samples.lnk -> C:\Program Files (x86)\RivaTuner Statistics Server\SDK\Samples () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\MSI Afterburner.lnk -> C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\ReadMe.lnk -> C:\Program Files (x86)\MSI Afterburner\Doc\ReadMe.pdf () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\Uninstall.lnk -> C:\Program Files (x86)\MSI Afterburner\Uninstall.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\SDK\MSI Afterburner localization reference.lnk -> C:\Program Files (x86)\MSI Afterburner\SDK\Doc\Localization reference.pdf () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\SDK\MSI Afterburner skin format reference.lnk -> C:\Program Files (x86)\MSI Afterburner\SDK\Doc\USF skin format reference.pdf () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner\SDK\Samples.lnk -> C:\Program Files (x86)\MSI Afterburner\SDK\Samples () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed\Documentation.lnk -> C:\LFS\docs (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed\LFS Manual.lnk -> C:\LFS\data\icons\LFS_GEN.ico (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed\LFS.lnk -> C:\LFS\LFS.exe (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed\README.lnk -> C:\LFS\README.txt (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live for Speed\Uninstall LFS.lnk -> C:\LFS\UninstallLFS.exe (No File) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iRacing\iRacing Beta UI.lnk -> C:\Program Files (x86)\iRacing\iRacingSim64DX11.exe (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iRacing\iRacing Member Website.lnk -> C:\Program Files (x86)\iRacing\iRacingSim64Dx11.exe (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\Pinball.lnk -> C:\Program Files (x86)\Microsoft Games\Pinball\pinball.exe (Cinematronics) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DroidCam\DroidCam Client.lnk -> C:\Program Files (x86)\DroidCam\DroidCamApp.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DroidCam\Uninstall.lnk -> C:\Program Files (x86)\DroidCam\Uninstall.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\internet explorer\iexplore.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gyazo GIF.lnk -> C:\Program Files (x86)\Gyazo\GyazoGIF.exe (Nota Inc.) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Gyazo.lnk -> C:\Program Files (x86)\Gyazo\Gyazowin.exe (Nota Inc.) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk -> C:\Users\Kurt\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\irFFB.lnk -> C:\Users\Kurt\Documents\irFFB.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Motion Cockpit View Activator.lnk -> C:\Users\Kurt\Documents\iRacing\Motion_Cockpit_View_Activator.exe (Stéphane TURPIN) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Oculus.lnk -> C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\OculusDebugTool - Shortcut.lnk -> C:\Users\Kurt\Documents\oculus-diagnostics\OculusDebugTool.exe (Oculus VR) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PC Sleep.lnk -> C:\Program Files (x86)\PC Sleep\PC Sleep.exe (www.pc-sleep.com) Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Trading Paints.lnk -> C:\Program Files (x86)\Rhinode LLC\Trading Paints\Trading Paints.exe () Shortcut: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Volume Mixer.lnk -> C:\Windows\System32\SndVol.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Roaming\ClassicShell\Pinned\startscreen.lnk -> C:\Program Files\Classic Shell\ClassicStartMenu.exe (No File) Shortcut: C:\Users\Kurt\AppData\Local\NVIDIA Corporation\Shield Apps\Madden19.lnk -> C:\Program Files (x86)\Origin Games\Madden NFL 19\Madden19.exe (No File) Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk -> C:\Users\Kurt\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -> C:\Windows\explorer.exe,-30 Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.lnk -> C:\Windows\System32\diskmgmt.msc () Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.lnk -> C:\Windows\System32\eventvwr.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) Shortcut: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) Shortcut: C:\Users\Public\Desktop\Oculus.lnk -> C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) Shortcut: C:\Users\Public\Desktop\paint.net.lnk -> C:\Program Files\paint.net\PaintDotNet.exe (dotPDN LLC) ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) -> --reset-config --reset-plugins-cache vlc://quit ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) -> -Iskins ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Thrustmaster FFB Racing wheel\Update Service.lnk -> C:\Program Files\Guillemot\tools\tmStartWUW.exe () -> "ftp.thrustmaster.com" "/pub/webupdate/T500RS" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /7 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision preview pack 1.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /show ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Database Compare.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\DCF\DATABASECOMPARE.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Office Upload Center.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\MSOUC.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools\Spreadsheet Compare.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\DCF\SPREADSHEETCOMPARE.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Database Compare.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\DCF\DATABASECOMPARE.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Office Upload Center.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\MSOUC.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Spreadsheet Compare.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\DCF\SPREADSHEETCOMPARE.EXE" ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus\McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.766\McUICnt.exe (McAfee, Inc.) -> SecurityScanner.dll ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Uninstall Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\unins001.exe () -> /LOG ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\javacpl.exe (Oracle Corporation) -> -tab about ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\javacpl.exe (Oracle Corporation) -> -tab update ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo\Gyazo Settings.lnk -> C:\Program Files (x86)\Gyazo\GyStation.exe (Nota Inc.) -> /option ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\SupportAssist\SupportAssist.lnk -> C:\Program Files\Dell\SupportAssist\pcdlauncher.exe (PC-Doctor, Inc.) -> -lloc dsc ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATVO\ATVO.lnk -> C:\Windows\Installer\{604CC657-16CC-4DE2-8D80-7C67595A20B7}\_F2E22C1EE826240485F61D.exe () -> ATVO ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ATVO\ThemeEditor.lnk -> C:\Windows\Installer\{604CC657-16CC-4DE2-8D80-7C67595A20B7}\_B68721643D36E4B95C3190.exe () -> ThemeEditor ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1 ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Oculus\Uninstall Oculus.lnk -> C:\Program Files\Oculus\OculusSetup.exe (Oculus VR, LLC) -> /uninstall ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) -> --sendto ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\KQM\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\KQM\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\Kurt\Documents\BROADCAST\ATVO.lnk -> C:\Windows\Installer\{604CC657-16CC-4DE2-8D80-7C67595A20B7}\_2C3624BE83EAC6EDBB90C2.exe () -> ATVO ShortcutWithArgument: C:\Users\Kurt\Documents\BROADCAST\ThemeEditor.lnk -> C:\Windows\Installer\{604CC657-16CC-4DE2-8D80-7C67595A20B7}\_0B0D8E4001E9C534BF4EF6.exe () -> ThemeEditor ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc\Discord.lnk -> C:\Users\Kurt\AppData\Local\Discord\Update.exe (GitHub) -> --processStart Discord.exe ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dean Netherton\iRacing Application Updates.lnk -> C:\Users\Kurt\AppData\Local\Apps\2.0\BPX4G7YT.7C9\M8CVKQZD.J18\irac..tion_0000000000000000_0001.0000_0eb8f7da01277921\iRacingApplicationVersionManger.exe () -> -update ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\iRacing.com™ Race Guide.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=phiocplhljmeipikdanklondaeanchip ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TeamViewer.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=oooiobdokpcfdlahlmcddobejikcmkfo ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\VIPBox.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ocifmfjojonabdfdbahgjkhhoneinkkd ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\SendTo\TeamViewer.lnk -> C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) -> --sendto ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation) -> /recycle ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Discord.lnk -> C:\Users\Kurt\AppData\Local\Discord\Update.exe (GitHub) -> --processStart Discord.exe ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e15728732a64f572\Floating Player.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ekajjllcmeckibblgckgoceinmmgnfop ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\aeea6001c9fdcab9\Click&Clean.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ghgabhipcejejjmhhchfonmamedcbeod ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\8297e8d79fb1e2ab\Floating for YouTube™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=jjphmlaoffndcnecccgemfdaaoighkel ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\78c8ec8ac08a8d81\YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=adnlfjpnmidfimlkaohpidplnoimahfh ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - Network Connections.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> ::{7007ACC7-3202-11D1-AAD2-00805FC1270E} ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\06 - System.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.System ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\08 - Power Options.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.PowerOptions ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group3\10 - Programs and Features.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.ProgramsAndFeatures ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\Kurt\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageNetworkStatus ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DeviceManager ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPagePCSystemInfo ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageScreenPowerAndSleep ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.lnk -> C:\Windows\ImmersiveControlPanel\systemsettings.exe (Microsoft Corporation) -> page=SettingsPageAppsSizes ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{2559a1f8-21d7-11d4-bdaf-00c04f60b9f0} ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{52205fd8-5dfb-447d-801a-d0b52f2e83e1} ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.lnk -> C:\Windows\System32\Taskmgr.exe (Microsoft Corporation) -> /0 ShortcutWithArgument: C:\Users\OVRLibraryService\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> shell:::{3080F90D-D7AD-11D9-BD98-0000947B0257} InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vJoy\vJoy Home.url -> URL: hxxp://vjoystick.sourceforge.net/site InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vJoy\vJoy SDK.url -> URL: hxxp://vjoystick.sourceforge.net/redirect_download_vJoy2SDK.php InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam\Steam Support Center.url -> URL: hxxp://support.steampowered.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url -> URL: hxxp://java.com/help InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.url -> URL: hxxp://java.com/ InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iRacing\members.iRacing.com (race, test, stats, forums).url -> URL: hxxp://members.iRacing.com InternetURL: C:\Users\Kurt\Favorites\Bing.url -> URL: hxxp://go.microsoft.com/fwlink/p/?LinkId=255142 InternetURL: C:\Users\Kurt\Favorites\Dell\Dell Auction.url -> URL: hxxp://www.dellauction.com/ InternetURL: C:\Users\Kurt\Favorites\Dell\Dell.url -> URL: hxxp://www.dell.com/ InternetURL: C:\Users\Kurt\Favorites\Dell\Support.Dell.Com.url -> URL: hxxp://www.dell.com/support/home InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Assetto Corsa.url -> URL: steam://rungameid/244210 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\iRacing.url -> URL: steam://rungameid/266410 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\LIV.url -> URL: steam://rungameid/755540 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\rFactor 2.url -> URL: steam://rungameid/365960 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\Rocket League.url -> URL: steam://rungameid/252950 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\SteamVR (2).url -> URL: steam://rungameid/250820 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\SteamVR Performance Test.url -> URL: steam://rungameid/323910 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\SteamVR.url -> URL: steam://rungameid/250820 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam\TrackMania Nations Forever.url -> URL: steam://rungameid/11020 InternetURL: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dean Netherton\iRacing Application Version Mananger online support.url -> BASEURL: hxxps://github.com/vipoo/iRacingApplicationVersionManager/blob/master/README.md URL: hxxps://github.com/vipoo/iRacingApplicationVersionManager/blob/master/README.md ==================== End of Shortcut.txt =============================
  17. KQuist95

    Wondershare Helper Compact

    addition.txt Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14.01.2019 01 Ran by Kurt (15-01-2019 19:15:46) Running from C:\Users\Kurt\Desktop\PC Management Windows 10 Home Version 1803 17134.523 (X64) (2018-05-14 17:41:32) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1188590385-209233840-2562061582-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1188590385-209233840-2562061582-503 - Limited - Disabled) Guest (S-1-5-21-1188590385-209233840-2562061582-501 - Limited - Disabled) Kurt (S-1-5-21-1188590385-209233840-2562061582-1001 - Administrator - Enabled) => C:\Users\Kurt Kurt Q (S-1-5-21-1188590385-209233840-2562061582-1002 - Administrator - Enabled) => C:\Users\Kurt Q WDAGUtilityAccount (S-1-5-21-1188590385-209233840-2562061582-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\uTorrent) (Version: 3.5.4.44520 - BitTorrent Inc.) 7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov) Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.114 - Adobe Systems Incorporated) Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.114 - Adobe Systems Incorporated) Alcor Micro USB Card Reader Driver (HKLM-x32\...\{2282AFD7-5074-4BC6-B1F7-205AAC8F6AC9}) (Version: 18.6.1844.34416 - Alcor Micro Corp.) Hidden Alcor Micro USB Card Reader Driver (HKLM-x32\...\InstallShield_{2282AFD7-5074-4BC6-B1F7-205AAC8F6AC9}) (Version: 18.6.1844.34416 - Alcor Micro Corp.) Apple Mobile Device Support (HKLM\...\{C29B636B-9015-4ED1-A12F-6375A337F23B}) (Version: 11.4.1.46 - Apple Inc.) ATVO Launcher (HKLM-x32\...\{604CC657-16CC-4DE2-8D80-7C67595A20B7}) (Version: 1.0.0 - Appgineer.in) CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden Chrome Remote Desktop Host (HKLM-x32\...\{F51A03C4-2DD0-43B0-900F-EAD1C45DC542}) (Version: 71.0.3578.15 - Google Inc.) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.) CrewChiefV4 (HKLM-x32\...\{E0E8894A-64F5-4165-BD9D-B5A01D29ABF7}) (Version: 4.9.5.9 - Britton IT Ltd) CyberLink Media Suite Essentials (HKLM-x32\...\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 12 - CyberLink Corp.) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Dell Data Vault (HKLM\...\{2E55EEFD-2162-4A7D-9158-EDB0305603A6}) (Version: 4.4.1.0 - Dell Inc.) Hidden Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP) Dell Help & Support (HKLM\...\{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Hidden Dell Help & Support (HKLM-x32\...\InstallShield_{457EFE69-8F49-43E0-80F9-1DEF4F7690C2}) (Version: 2.5.23.0 - Dell Inc.) Dell Product Registration (HKLM-x32\...\InstallShield_{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.) Dell SupportAssist (HKLM\...\{E98E94E2-12D1-48E5-AC69-2C312F466136}) (Version: 3.1.0.142 - Dell Inc.) Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 2.0.6875.668 - Dell) Dell Update (HKLM-x32\...\{D8AE5F9D-647C-49B4-A666-1C20B44EC0E1}) (Version: 2.1.3.0 - Dell Inc.) Discord (HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\Discord) (Version: 0.0.302 - Discord Inc.) DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 417.22 - NVIDIA Corporation) Hidden erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden FFB Racing Wheel drivers (HKLM-x32\...\{28B758EA-5C83-48B1-B352-C70F12C73F5A}) (Version: 1.TTRS.2018 - Thrustmaster) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 71.0.3578.98 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden Gyazo 3.4.1.0 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.) Intel(R) Chipset Device Software (HKLM-x32\...\{fb610cea-ba50-4d4b-a717-cf025419035c}) (Version: 10.1.1.13 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1054 - Intel Corporation) Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 20.2 - Intel) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4565 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.7.5.1025 - Intel Corporation) Intel(R) Ready Mode Technology (HKLM\...\{7331913F-E841-469A-B151-1046F1889E7B}) (Version: 1.1.70.518 - Intel Corporation) Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.866.0 - Intel Corporation) Hidden Intel(R) Trusted Connect Services Client (HKLM-x32\...\{246c6cc0-9810-4728-9a29-28474de2eec5}) (Version: 1.47.866.0 - Intel Corporation) Hidden Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) iRacing Application Version Mananger (HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\eb4c5a1253480d25) (Version: 1.0.0.27 - Dean Netherton) iRacing.com Race Simulation (HKLM-x32\...\{CBBB3C80-76F5-42B5-92A6-C4BF84796DCB}) (Version: 1.01.0650 - iRacing.com Motorsport Simulations) Java 8 Update 201 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180201F0}) (Version: 8.0.2010.9 - Oracle Corporation) Jimmie Johnson Spotter-Cuss Pack v6.71 (HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\Jimmie Johnson Spotter-Cuss Pack v6.71) (Version: - ) Joel Real Timing 1.25.9.2 (HKLM-x32\...\{1A0CE541-E8CE-417F-AD05-4981E4978AEF}_is1) (Version: 1.25.9.2 - Joel Guez) LibreOffice 5.2.3.3 (HKLM-x32\...\{30605C95-A3A0-4A08-AD58-9AE7ABA47B70}) (Version: 5.2.3.3 - The Document Foundation) Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.) Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes) Maxx Audio Installer (x64) (HKLM\...\{307032B2-6AF2-46D7-B933-62438DEB2B9A}) (Version: 2.6.6073.1 - Waves Audio Ltd.) Hidden McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.766.1 - McAfee, Inc.) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.8.20721 - McAfee, Inc.) Microsoft Keyboard Layout Creator 1.4 (HKLM-x32\...\{99E66BC9-E4B6-485F-ABFC-31EFCE36DFDF}) (Version: 1.4.6000 - Microsoft Corp.) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.11126.20196 - Microsoft Corporation) Microsoft OneDrive (HKU\.DEFAULT\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\OneDriveSetup.exe) (Version: 18.222.1104.0007 - Microsoft Corporation) Microsoft Server Speech Platform Runtime (x86) (HKLM-x32\...\{22CB8ED7-DF57-4864-BD04-F63B9CE4B494}) (Version: 11.0.7400.345 - Microsoft Corporation) Microsoft Server Speech Recognition Language - TELE (en-US) (HKLM-x32\...\{66D57636-BD4B-402F-9E7D-5E89C28C8136}) (Version: 11.0.7400.335 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (HKLM-x32\...\{6e8f74e0-43bd-4dce-8477-6ff6828acc07}) (Version: 11.0.51106.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x64) - 14.11.25325 (HKLM-x32\...\{6c6356fe-cbfa-4944-9bed-a9e99f45cb7a}) (Version: 14.11.25325.0 - Microsoft Corporation) Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 64.0 (x64 en-US) (HKLM\...\Mozilla Firefox 64.0 (x64 en-US)) (Version: 64.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 61.0.2 - Mozilla) MSI Afterburner 4.5.0 (HKLM-x32\...\Afterburner) (Version: 4.5.0 - MSI Co., LTD) NASCAR® Racing 2003 Season (HKLM-x32\...\{ACC2E059-40E9-4464-B18D-C9BDD9A02CED}) (Version: - Sierra Entertainment) NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.12 - NVIDIA Corporation) Hidden NVIDIA 3D Vision Controller Driver 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation) NVIDIA 3D Vision Driver 417.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 417.22 - NVIDIA Corporation) NVIDIA GeForce Experience 3.16.0.122 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.16.0.122 - NVIDIA Corporation) NVIDIA Graphics Driver 417.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 417.22 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.38.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.4 - NVIDIA Corporation) NVIDIA PhysX System Software 9.18.0907 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.18.0907 - NVIDIA Corporation) OBS Studio (HKLM-x32\...\OBS Studio) (Version: 18.0.0 - OBS Project) Oculus (HKLM\...\Oculus) (Version: ❤️ - Oculus VR, LLC) Oculus Rift DK2 Sensor Driver (HKLM\...\{F786EF4E-73FE-4700-AC19-FFC0B2298F20}) (Version: 1.0.0.0 - Oculus VR, LLC) Hidden Oculus Rift Monitor Driver (HKLM\...\{E932D5B4-547A-4959-B642-3816836283E3}) (Version: 1.0.1.0 - Oculus VR, LLC) Hidden Oculus Rift Sensor Driver (HKLM\...\{E724ED40-8962-4987-901D-57AC8C9E41CD}) (Version: 1.0.20.0 - Oculus VR, LLC) Hidden Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.11126.20196 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.11126.20196 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.11126.20196 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.11126.20196 - Microsoft Corporation) Hidden paint.net (HKLM\...\{E8FA8815-3817-4128-A814-E2EAC456ADF0}) (Version: 4.0.21 - dotPDN LLC) PC Sleep (HKLM-x32\...\{11BD0F20-27DC-4584-AD10-9E99F32F8501}) (Version: 2.2.0 - www.pc-sleep.com) Product Registration (HKLM\...\{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7544 - Realtek Semiconductor Corp.) REALTEK Wireless LAN and Bluetooth Driver (HKLM-x32\...\{6BFBB929-C278-42B3-8065-FF1178E071B8}) (Version: 13.231.243 - REALTEK Semiconductor Corp.) RivaTuner Statistics Server 7.1.0 (HKLM-x32\...\RTSS) (Version: 7.1.0 - Unwinder) Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.4.0 - Rockstar Games) Soda Player (HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\sodaplayer) (Version: 1.4.2 - Soda Player) Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.7.0 - Sophos Limited) Spotify (HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\Spotify) (Version: 1.0.96.181.gf6bc1b6b - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.1.8 - TeamSpeak Systems GmbH) TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.2.5287 - TeamViewer) TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp) The Digital Race Engineer version 2.6 (HKLM-x32\...\{490EC064-009E-4E95-8A17-873F490D90F7}_is1) (Version: 2.6 - AWE) Trading Paints (HKLM-x32\...\{D3D19A58-A7DA-43D1-8C77-E5DC9F584B59}) (Version: 1.4.1 - Rhinode LLC) Trading Paints (HKLM-x32\...\{DC5089FC-B422-44E8-8FDE-26D5A1F53614}) (Version: 2.0.9 - Rhinode LLC) Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{9CBA860F-7437-4A75-941C-8EF559F2D145}) (Version: 2.52.0.0 - Microsoft Corporation) Virtual Racing School (VRS) (HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\Virtual Racing School (VRS)) (Version: 1.0.0 - Smarty Co.) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) vJoy Device Driver 2.1.8.38 (HKLM\...\{8E31F76F-74C3-47F1-9550-E041EEDC5FBB}_is1) (Version: 2.1.8.38 - Shaul Eizikovich) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Vulkan Run Time Libraries 1.0.65.1 (HKLM\...\VulkanRT1.0.65.1-2) (Version: 1.0.65.1 - LunarG, Inc.) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinRAR 5.61 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.61.1 - win.rar GmbH) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers1: [BtSendToMenuEx] -> {CF24E6B8-F148-4BCB-9108-ADF313966E80} => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\DevMenuExt.dll [2014-07-03] (Realtek Semiconductor Corporation) ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-08-19] (Cyberlink) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-03] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-03] (Alexander Roshal) ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2015-08-19] (Cyberlink) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> No File ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-11-29] (NVIDIA Corporation) ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-05-21] (Igor Pavlov) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-09-03] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-09-03] (Alexander Roshal) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {03A85A5B-C487-48CE-8EF3-6D4FA79382E8} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2019-01-02] (Microsoft Corporation) Task: {06400310-E676-4848-9E95-AAABE489FD2F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2019-01-12] (Microsoft Corporation) Task: {0BA2AECB-595D-4C9A-8E0E-1E4B22D64EAC} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-10] (Microsoft Corporation) Task: {172B3230-E737-4E65-9289-34D76DC73BA4} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2017-09-14] (PC-Doctor, Inc.) Task: {19BFCE06-0375-44A4-ABD5-A02C085C6E65} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-13] (Google Inc.) Task: {1BD6F8C8-3E40-400D-8667-3C7CAB6DA3A5} - \{7EAA52E9-66C8-FBD8-BB44-020AB9973D4F}\Pemahabu -> No File <==== ATTENTION Task: {1CFBB589-42D0-4B7C-B759-C66445BA17E8} - System32\Tasks\S-1-5-21-1188590385-209233840-2562061582-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-12-08] (Microsoft Corporation) Task: {2AED3849-38E8-4273-B4B7-CFB9FD0B9657} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-11-16] (NVIDIA Corporation) Task: {32EADECD-FD62-4219-9B3F-AA986BB6DC3D} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION Task: {359B19C2-7EA4-46C1-AA56-270E197E3871} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2017-10-11] (Intel(R) Corporation) Task: {39303B74-16D7-4282-9C44-B5A66AD2CE8C} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2019-01-12] (Microsoft Corporation) Task: {39522FD4-0DB4-4D1B-9AB0-059415B2166A} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [2019-01-12] (Microsoft Corporation) Task: {406295B2-F3C3-410C-B16C-3C8CE81E3366} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-11-16] (NVIDIA Corporation) Task: {4CE569B9-A25D-47BF-A587-AE53DA3055B3} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-10] (Microsoft Corporation) Task: {4DF4F32F-B68E-445A-9D11-EF9EB2471FE1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-10] (Microsoft Corporation) Task: {52850552-43A3-47F4-9405-5DC3DCA5BA2C} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-11-16] (NVIDIA Corporation) Task: {53D8D608-C6CB-479D-BD7C-C94B8859939E} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2018-10-04] (Nota Inc.) Task: {63E8571E-F656-4534-B907-08CD52A50B3A} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-12-16] (Oracle Corporation) Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] () Task: {69B7FD48-E092-4A5D-BE26-BC9F6D349FC6} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLVDLauncher.exe [2015-01-28] (CyberLink Corp.) Task: {6B3732F0-97C8-4576-9CA6-735211AF3132} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe Task: {6C3075A3-F120-411C-98F0-8C4C816E37E8} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe [2019-01-12] (Microsoft Corporation) Task: {73628091-97E2-4FC4-A338-FEB7008DD452} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-11-16] (NVIDIA Corporation) Task: {7741B70A-7595-4FF2-8724-92503285933A} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2018-11-16] (NVIDIA Corporation) Task: {7DCBA657-7D37-4426-8232-2CF2A46E32BA} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistInstaller.exe [2018-12-12] (Dell Inc.) Task: {7EF0BF73-1174-456C-AF77-60E1D0391860} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2019-01-02] (Microsoft Corporation) Task: {7FA28BE9-2D35-470C-BFA3-86A99729667C} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2019-01-12] (Microsoft Corporation) Task: {8105F1EC-93C3-4A26-9467-859E5CDB1366} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2018-11-16] (NVIDIA Corporation) Task: {82C92FB3-AB6C-40EE-BB36-B615ACCE50A8} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2018-10-04] (Nota Inc.) Task: {8394D472-8459-4B5B-B022-99B6865D636D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2019-01-12] (Microsoft Corporation) Task: {85ACA143-1105-411A-BCAF-393090EB9482} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2019-01-15] (AVAST Software) Task: {8A5CB8F2-0AF1-47C9-B74F-40B39A04CD8A} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_114_pepper.exe [2019-01-08] (Adobe Systems Incorporated) Task: {8AC06FBC-AEC8-4082-B4DD-ED07D8307449} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2019-01-08] (Adobe Systems Incorporated) Task: {9BDA39BE-37A1-4C37-89BB-35E5068AB17B} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-11-16] (NVIDIA Corporation) Task: {9DF2756B-6021-42C4-882C-F8FCB97D1001} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2018-11-16] (NVIDIA Corporation) Task: {9E613129-2CBC-4D30-A5BC-1FB4D28D8D94} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-10] (Microsoft Corporation) Task: {9EB01845-BE0D-42DA-9B4B-B77FFA6202CC} - System32\Tasks\AdwCleaner_onReboot => C:\Users\Kurt\Desktop\AdwCleaner.exe Task: {9F4B42F4-B1C2-488C-BC67-226F4C8AB270} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2017-09-14] (PC-Doctor, Inc.) Task: {AB539741-D530-4654-AC55-50CD2BC8C779} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2019-01-12] (Microsoft Corporation) Task: {C544BF18-B7E0-4EED-8399-8B562928EDC3} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2018-11-16] (NVIDIA Corporation) Task: {CA8A1B15-DFC4-4423-A20D-CC16AC18BAD6} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2018-11-16] (NVIDIA Corporation) Task: {D0FF3947-A5B9-4582-A781-3F89840EE3C3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-13] (Google Inc.) Task: {D2529323-D808-42A2-8192-356CDAE1EE8F} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe Task: {D4196FC9-3307-4213-A045-65AED9D3A6CD} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2018-11-16] (NVIDIA Corporation) Task: {DC8C1666-0D8B-48E7-979C-5D606F12F0A0} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe Task: {DD383F1E-619A-41D3-8D7A-1061BA02B21D} - System32\Tasks\D3DGearRawFrameCaptureTask => C:\Program Files (x86)\iRacing\d3dGear.exe [2018-12-04] (D3DGear Technologies.) Task: {E28CE82F-3B83-40D9-928A-1413F4E445B0} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_114_Plugin.exe [2019-01-08] (Adobe Systems Incorporated) Task: {F7EC2F1E-E704-467A-A253-037BDE26E9BA} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe [2015-08-18] (CyberLink) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe Task: C:\WINDOWS\Tasks\RunDLC.job => cmd c sc start Dell Help SupportWORKGROUP DESKTOP J7JIURT ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\iRacing.com™ Race Guide.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=phiocplhljmeipikdanklondaeanchip ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\TeamViewer.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=oooiobdokpcfdlahlmcddobejikcmkfo ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\VIPBox.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ocifmfjojonabdfdbahgjkhhoneinkkd ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\e15728732a64f572\Floating Player.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ekajjllcmeckibblgckgoceinmmgnfop ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\aeea6001c9fdcab9\Click&Clean.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=ghgabhipcejejjmhhchfonmamedcbeod ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\8297e8d79fb1e2ab\Floating for YouTube™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=jjphmlaoffndcnecccgemfdaaoighkel ShortcutWithArgument: C:\Users\Kurt\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\78c8ec8ac08a8d81\YouTube.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=adnlfjpnmidfimlkaohpidplnoimahfh ==================== Loaded Modules (Whitelisted) ============== 2015-05-19 10:11 - 2015-05-19 10:11 - 000007680 _____ () C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe 2016-06-06 16:35 - 2014-04-14 19:59 - 000253776 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2018-08-13 14:53 - 2018-11-16 05:55 - 001314672 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2019-01-15 17:48 - 2017-11-29 09:11 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2019-01-15 17:48 - 2017-11-29 09:11 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll 2018-04-11 17:34 - 2018-04-11 17:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll 2018-04-11 17:34 - 2018-04-11 17:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll 2018-12-12 10:55 - 2018-11-08 20:17 - 002759680 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll 2019-01-12 18:58 - 2019-01-12 18:58 - 001760696 _____ () C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe 2019-01-09 14:47 - 2019-01-01 00:42 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2018-12-11 10:26 - 2018-12-11 10:34 - 034870272 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Video.UI.exe 2018-12-11 10:26 - 2018-12-11 10:30 - 000292352 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\SharedUI.dll 2017-12-01 03:37 - 2017-12-01 03:39 - 000902656 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Microsoft.Membership.MeControl.UI.Xaml.dll 2018-11-28 23:13 - 2018-11-28 23:14 - 004202208 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2018-12-11 10:26 - 2018-12-11 10:27 - 005967872 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\EntCommon.dll 2018-12-11 10:26 - 2018-12-11 10:30 - 009072128 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\EntPlat.dll 2016-06-06 16:43 - 2014-07-03 10:22 - 000277720 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\SkypePlugin.exe 2018-07-11 18:03 - 2018-07-11 18:03 - 001922224 _____ () C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.1000_x64__8wekyb3d8bbwe\Microsoft.Applications.Telemetry.Windows.dll 2018-06-03 19:42 - 2018-06-03 19:42 - 000166912 _____ () C:\Users\Kurt\Documents\irFFB.exe 2019-01-09 13:04 - 2019-01-09 13:04 - 002587968 _____ () C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1466\libprotobuf.dll 2018-08-13 14:54 - 2018-11-16 05:54 - 101251952 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll 2018-08-13 14:54 - 2018-11-16 05:54 - 004619632 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libglesv2.dll 2018-08-13 14:54 - 2018-11-16 05:54 - 000108400 _____ () C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\libegl.dll 2018-12-17 19:01 - 2018-12-11 23:12 - 002682336 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\swiftshader\libglesv2.dll 2018-12-17 19:01 - 2018-12-11 23:12 - 000156640 _____ () C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\swiftshader\libegl.dll 2016-06-06 16:34 - 2014-12-08 01:28 - 000627672 _____ () C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMediaLibrary.dll 2014-12-08 16:28 - 2014-12-08 16:28 - 000016856 _____ () C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvcPS.dll 2018-08-13 14:53 - 2018-11-16 05:55 - 001032560 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2018-03-27 12:41 - 2018-03-27 12:41 - 000134616 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll 2017-11-08 23:44 - 2017-11-08 23:44 - 001244304 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\sharepoint.com -> hxxps://clc365-files.sharepoint.com ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-10-30 01:24 - 2018-09-12 09:58 - 000002268 _____ C:\WINDOWS\system32\drivers\etc\hosts 0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly 0.0.0.0 tracking.opencandy.com.s3.amazonaws.com 0.0.0.0 media.opencandy.com 0.0.0.0 cdn.opencandy.com 0.0.0.0 tracking.opencandy.com 0.0.0.0 api.opencandy.com 0.0.0.0 api.recommendedsw.com 0.0.0.0 installer.betterinstaller.com 0.0.0.0 installer.filebulldog.com 0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net 0.0.0.0 inno.bisrv.com 0.0.0.0 nsis.bisrv.com 0.0.0.0 cdn.file2desktop.com 0.0.0.0 cdn.goateastcach.us 0.0.0.0 cdn.guttastatdk.us 0.0.0.0 cdn.inskinmedia.com 0.0.0.0 cdn.insta.oibundles2.com 0.0.0.0 cdn.insta.playbryte.com 0.0.0.0 cdn.llogetfastcach.us 0.0.0.0 cdn.montiera.com 0.0.0.0 cdn.msdwnld.com 0.0.0.0 cdn.mypcbackup.com 0.0.0.0 cdn.ppdownload.com 0.0.0.0 cdn.riceateastcach.us 0.0.0.0 cdn.shyapotato.us 0.0.0.0 cdn.solimba.com 0.0.0.0 cdn.tuto4pc.com 0.0.0.0 cdn.appround.biz 0.0.0.0 cdn.bigspeedpro.com 0.0.0.0 cdn.bispd.com 2017-10-04 23:06 - 2019-01-05 12:47 - 000000590 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics 2.168.137.136 XBOXONE.mshome.net # 2019 1 4 10 22 31 39 166 66 351 51 ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Program Files\Oculus\Support\oculus-runtime;C:\Program Files (x86)\Intel\iCLS Client\;c:\program files\oculus\support\oculus-runtime;c:\programdata\oracle\java\javapath;c:\program files\intel\icls client\;c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\windows\system32\windowspowershell\v1.0\;c:\program files (x86)\iracing;c:\program files (x86)\windows live\shared;c:\program files (x86)\iracing;c:\windows\system32;c:\windows;c:\windows\system32\wbem;c:\windows\system32\windowspowershell\v1.0\;c:\windows\system32\openssh\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;c:\program files (x86)\iracing;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;c:\program files (x86)\iracing HKU\S-1-5-21-1188590385-209233840-2562061582-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kurt\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\1303900.jpg DNS Servers: 75.75.75.75 - 75.75.76.76 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk" HKLM\...\StartupApproved\StartupFolder: => "iRacingSetupSyncLauncher.lnk" HKLM\...\StartupApproved\Run: => "WavesSvc" HKLM\...\StartupApproved\Run: => "IAStorIcon" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run: => "Malwarebytes TrayApp" HKLM\...\StartupApproved\Run: => "AvgUi" HKLM\...\StartupApproved\Run: => "AVGUI.exe" HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run: => "Wondershare Helper Compact.exe" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "LWS" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\StartupFolder: => "HRC.exe" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "Spotify Web Helper" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "Spotify" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "BlueStacks Agent" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "Trading Paints" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "uTorrent" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "Speech Recognition" HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\StartupApproved\Run: => "Chromium" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{134861B6-574A-4A3E-B194-FB2AF8671B4E}] => (Allow) C:\Program Files\Oculus\Software\Software\bandai-namco-entertainment-project-cars\Tools\TweakIt\TweakIt.exe No File FirewallRules: [{405D1418-CD4F-4A14-B3E5-E90932DB32BC}] => (Allow) C:\Program Files\Oculus\Software\Software\bandai-namco-entertainment-project-cars\Tools\TweakIt\TweakIt.exe No File FirewallRules: [{85FEF612-03C5-47AF-B5BA-A0A8D268365D}] => (Allow) C:\Program Files\Oculus\Software\Software\bandai-namco-entertainment-project-cars\pCARSOculus64.exe No File FirewallRules: [{ACE4DAD1-E90E-429F-BDF3-308A96B051B0}] => (Allow) C:\Program Files\Oculus\Software\Software\bandai-namco-entertainment-project-cars\pCARSOculus64.exe No File FirewallRules: [{9746482F-33B6-40BF-B927-B846DB4BC2CD}] => (Allow) C:\Program Files\Oculus\Software\Software\bandai-namco-entertainment-project-cars\NVShaderPerf.exe No File FirewallRules: [{BFA11D0C-A5DB-4B0E-9E41-D8587BBFCE03}] => (Allow) C:\Program Files\Oculus\Software\Software\bandai-namco-entertainment-project-cars\NVShaderPerf.exe No File FirewallRules: [{AE8FB283-030E-40BF-9832-A32CAB2A15A8}] => (Allow) C:\Program Files\Oculus\Software\Software\bandai-namco-entertainment-project-cars\AwesomiumProcess.exe No File FirewallRules: [{AE6AE2C0-29B5-45E3-AE54-4CFE0A2F29E4}] => (Allow) C:\Program Files\Oculus\Software\Software\bandai-namco-entertainment-project-cars\AwesomiumProcess.exe No File FirewallRules: [{E99280EC-AF77-47BC-AC93-66227E67A110}] => (Allow) C:\Program Files\Oculus\Software\Software\epic-games-odin\Engine\Binaries\Win64\CrashReportClient.exe No File FirewallRules: [{FF005A4D-B8CD-43AE-9A9B-713A3598E786}] => (Allow) C:\Program Files\Oculus\Software\Software\epic-games-odin\Engine\Binaries\Win64\CrashReportClient.exe No File FirewallRules: [{3545EC71-3ECC-4F73-AFAC-3D7510367138}] => (Allow) C:\Program Files\Oculus\Software\Software\epic-games-odin\RoboRecall\Binaries\Win64\RoboRecall-Win64-Shipping.exe No File FirewallRules: [{75F0787D-8CA6-4A60-AC8E-3F9A21A50334}] => (Allow) C:\Program Files\Oculus\Software\Software\epic-games-odin\RoboRecall\Binaries\Win64\RoboRecall-Win64-Shipping.exe No File FirewallRules: [{2EE7B50A-29CE-4216-B0E8-6F86739235D0}] => (Allow) C:\Program Files\Oculus\Software\Software\epic-games-odin\RoboRecall\Binaries\Win64\RoboRecallModInstaller.exe No File FirewallRules: [{6FB840D7-879C-490B-9570-2301C2F18F18}] => (Allow) C:\Program Files\Oculus\Software\Software\epic-games-odin\RoboRecall\Binaries\Win64\RoboRecallModInstaller.exe No File FirewallRules: [UDP Query User{D255796C-7C4D-4C65-91A9-AF1666385BE7}C:\program files (x86)\steam\steamapps\common\rfactor 2\bin64\rfactor2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rfactor 2\bin64\rfactor2.exe (Studio 397) FirewallRules: [TCP Query User{9CF9C520-0E03-47B5-B117-0E37DE05AE2B}C:\program files (x86)\steam\steamapps\common\rfactor 2\bin64\rfactor2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rfactor 2\bin64\rfactor2.exe (Studio 397) FirewallRules: [UDP Query User{62C3655A-4BD8-48D6-AE53-E36D1920195F}C:\program files (x86)\steam\steamapps\common\rfactor 2\bin64\rfactor2 mod mode.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rfactor 2\bin64\rfactor2 mod mode.exe (Studio 397) FirewallRules: [TCP Query User{69B6B699-78B2-4BCE-A685-0AA7A9573AF7}C:\program files (x86)\steam\steamapps\common\rfactor 2\bin64\rfactor2 mod mode.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rfactor 2\bin64\rfactor2 mod mode.exe (Studio 397) FirewallRules: [UDP Query User{223DDABC-B875-4C25-8016-1D18538B79E9}C:\program files\windowsapps\xbmcfoundation.kodi_17.9.601.0_x86__4n2hpmxwrvr6p\kodi.exe] => (Allow) C:\program files\windowsapps\xbmcfoundation.kodi_17.9.601.0_x86__4n2hpmxwrvr6p\kodi.exe No File FirewallRules: [TCP Query User{96B91506-7B7B-4B9C-8156-EC82799349A7}C:\program files\windowsapps\xbmcfoundation.kodi_17.9.601.0_x86__4n2hpmxwrvr6p\kodi.exe] => (Allow) C:\program files\windowsapps\xbmcfoundation.kodi_17.9.601.0_x86__4n2hpmxwrvr6p\kodi.exe No File FirewallRules: [UDP Query User{AE31513B-7472-4C80-80BE-2E4149CD3FFF}C:\users\kurt\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\kurt\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc.) FirewallRules: [TCP Query User{B7724812-6EEE-466B-BDEF-18792BCBCDF7}C:\users\kurt\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\kurt\appdata\roaming\utorrent\utorrent.exe (BitTorrent Inc.) FirewallRules: [{DB9A6B9B-B24F-4843-AFAB-05CF9A320FA9}] => (Allow) C:\Users\Kurt\AppData\Roaming\uTorrent\updates\3.5.3_44358.exe (BitTorrent Inc.) FirewallRules: [{5139D932-E91C-4972-B928-6E3FD97E9282}] => (Allow) C:\Users\Kurt\AppData\Roaming\uTorrent\updates\3.5.3_44358.exe (BitTorrent Inc.) FirewallRules: [{07D90B96-F628-4357-B8F5-A7FA47C4BFD1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LIV\LIVApp.exe No File FirewallRules: [{32871FA7-A839-4EF5-8A0C-67EF73A94E97}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LIV\LIVApp.exe No File FirewallRules: [{30D28346-993E-4359-8F6C-C95E13BD1B4C}] => (Allow) LPort=1900 FirewallRules: [{D6F3E027-5D0C-404A-817F-9AAF1FA975B4}] => (Allow) LPort=2869 FirewallRules: [{B0AC4A31-5A60-4FE0-B7A0-763CCDFF31BB}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe No File FirewallRules: [UDP Query User{C963E73C-8FF2-4253-B14F-760B0D687B93}C:\joel real timing\timing.exe] => (Allow) C:\joel real timing\timing.exe () FirewallRules: [TCP Query User{51E19257-9E66-445D-8E3E-80C52ED5641D}C:\joel real timing\timing.exe] => (Allow) C:\joel real timing\timing.exe () FirewallRules: [{302A75F4-AAE9-4B35-ABC6-2A226D372E7A}] => (Allow) C:\Program Files (x86)\DroidCam\DroidCamApp.exe () FirewallRules: [{682B83B2-D32C-4292-99E4-38F0BBC665B6}] => (Allow) C:\Program Files (x86)\DroidCam\DroidCamApp.exe () FirewallRules: [{8E5F18FC-80A7-4F7C-926B-D012A5ABEDFF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\raceroom racing experience\Game\RRRE.exe No File FirewallRules: [{339F2A3F-7605-4278-AE11-33B464D8B94C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\raceroom racing experience\Game\RRRE.exe No File FirewallRules: [{C3E23071-5ADA-4359-8E99-8CAB522FEC1E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe No File FirewallRules: [{896BF3F3-12EF-47EE-9F5B-1244D2F1C65F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\raceroom racing experience\Game\x64\RRRE64.exe No File FirewallRules: [{58B30C8F-6A39-4B47-91A7-976F45993266}] => (Allow) C:\Program Files\Oculus\Software\Software\for-fun-labs-eleven-table-tennis-vr\pong_waves_vr.exe No File FirewallRules: [{1DCA3494-582C-42F0-A0C7-FFA0F08C412D}] => (Allow) C:\Program Files\Oculus\Software\Software\for-fun-labs-eleven-table-tennis-vr\pong_waves_vr.exe No File FirewallRules: [UDP Query User{D3C0C6AA-3E74-4324-ADE3-2C99EFE31BA0}C:\program files (x86)\steam\steamapps\common\assettocorsa\acs.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\assettocorsa\acs.exe () FirewallRules: [TCP Query User{0CDADB76-7327-4198-A59C-E1E8E02ADF92}C:\program files (x86)\steam\steamapps\common\assettocorsa\acs.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\assettocorsa\acs.exe () FirewallRules: [{777E8F81-2C82-4887-9F9E-1F3B12877F77}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TrackMania Nations Forever\TmForeverLauncher.exe No File FirewallRules: [{70524DE2-6D08-4104-B533-636D566318CB}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TrackMania Nations Forever\TmForeverLauncher.exe No File FirewallRules: [{0B086C32-4D0A-4248-A448-74169FA458B7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TrackMania Nations Forever\TmForever.exe No File FirewallRules: [{E97D60E5-E7CB-4124-A610-162DC66824BF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\TrackMania Nations Forever\TmForever.exe No File FirewallRules: [UDP Query User{6514AA56-CBCE-486F-BFC4-88A0F8CA67A5}C:\program files\oculus\software\software\nvidia-corporation-nvidia-vr-funhouse\engine\binaries\win64\ue4game-win64-shipping.exe] => (Allow) C:\program files\oculus\software\software\nvidia-corporation-nvidia-vr-funhouse\engine\binaries\win64\ue4game-win64-shipping.exe No File FirewallRules: [TCP Query User{A6B428B4-3316-49F0-B390-29BC2AEEF24D}C:\program files\oculus\software\software\nvidia-corporation-nvidia-vr-funhouse\engine\binaries\win64\ue4game-win64-shipping.exe] => (Allow) C:\program files\oculus\software\software\nvidia-corporation-nvidia-vr-funhouse\engine\binaries\win64\ue4game-win64-shipping.exe No File FirewallRules: [{9ED6C9BF-0F66-46D7-BCDB-D9E6EB6EB678}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\bin\OculusMedium.exe No File FirewallRules: [{23723D4C-C6AA-4E38-96CB-3EFA35059C06}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\bin\OculusMedium.exe No File FirewallRules: [{2E1F4BD0-5C80-4D53-BCA9-97FD7D44BBCC}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\bin\python35\python.exe No File FirewallRules: [{B88DAB38-D9ED-4476-B6EC-F96C181EB144}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\bin\python35\python.exe No File FirewallRules: [{A75FFB85-7A1E-41CC-9E27-2E97A98FD527}] => (Allow) C:\Program Files\Oculus\Software\Software\opus-studio-inc-pro-fishing-challenge-vr\Fishing\Binaries\Win64\Fishing.exe No File FirewallRules: [{B79417CC-AFB2-48F7-B3A9-8DDC14AF3671}] => (Allow) C:\Program Files\Oculus\Software\Software\opus-studio-inc-pro-fishing-challenge-vr\Fishing\Binaries\Win64\Fishing.exe No File FirewallRules: [{C426688E-74B6-46BA-8809-0DE390ECEAE5}] => (Allow) C:\Program Files\Oculus\Software\Software\opus-studio-inc-pro-fishing-challenge-vr\Engine\Binaries\Win64\CrashReportClient.exe No File FirewallRules: [{581896E6-87E0-4744-B318-4F090E88FA9D}] => (Allow) C:\Program Files\Oculus\Software\Software\opus-studio-inc-pro-fishing-challenge-vr\Engine\Binaries\Win64\CrashReportClient.exe No File FirewallRules: [{519DC43C-9422-4FDE-BC78-FF28F77B2C30}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File FirewallRules: [{86795D86-F648-453C-A62F-7F286DF214BC}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File FirewallRules: [{568343AE-8A55-45EF-B916-7E633DC92EA3}] => (Allow) LPort=80 FirewallRules: [{9681B0C4-44D8-4B48-BDE9-1F89B02D9B68}] => (Allow) C:\Program Files (x86)\3uTools\libXunlei\Download\MiniThunderPlatform.exe No File FirewallRules: [{F645644E-791E-4062-AD15-19C9C7A231B0}] => (Allow) C:\Program Files (x86)\3uTools\libXunlei\Download\MiniThunderPlatform.exe No File FirewallRules: [{0BE6A4A2-BBCB-40B7-9BE1-B0EF55FA3A46}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe (CyberLink Corp.) FirewallRules: [{4B8CAB8E-CAC4-4C09-B28C-1F5AB604312F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) FirewallRules: [{CFAEB09E-4AD1-4ABD-8982-4859828DD01C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation) FirewallRules: [{4AE08494-A026-4EEF-9327-1C63DF3BC69A}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe No File FirewallRules: [{CBD11A06-64BD-4F2A-AC8F-8579E3CB6F65}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe No File FirewallRules: [TCP Query User{F11487E7-A5C9-44EE-B242-C3B04BFD325C}C:\users\kurt\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kurt\appdata\roaming\spotify\spotify.exe (Spotify Ltd) FirewallRules: [UDP Query User{737E0CAD-E2FB-4C53-8CB5-972CB633A307}C:\users\kurt\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kurt\appdata\roaming\spotify\spotify.exe (Spotify Ltd) FirewallRules: [{19A190D4-ED1B-4594-8F3B-747A79F732DF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\assettocorsa\AssettoCorsa.exe (Kunos Simulazioni) FirewallRules: [{EDE21FBB-816B-4371-8AE3-26C103A06792}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\assettocorsa\AssettoCorsa.exe (Kunos Simulazioni) FirewallRules: [{F2BD9434-08BD-46AC-B7C2-D9EF8A4AACA0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe No File FirewallRules: [{439DB252-F8A1-43CB-8C4E-E7ABCC45A6E9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe No File FirewallRules: [{344BE58F-744D-4707-A633-72EB9888FF60}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen.exe No File FirewallRules: [{17792A7B-10E3-4BF8-BAC1-71C3D03BCFEF}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen.exe No File FirewallRules: [{A773670A-B40C-4FC8-AB85-5C9F70413065}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\Helper\win64\chromedriver.exe No File FirewallRules: [{81D8C1E0-17B4-4848-B079-8EF7DC9B66FF}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\Helper\win64\chromedriver.exe No File FirewallRules: [{81E45308-C213-4A53-9821-6B90B99E171E}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\Helper\win64\payload.exe No File FirewallRules: [{9A57B563-7549-4032-A76F-DB4F7B9AF648}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\Helper\win64\payload.exe No File FirewallRules: [{7C3192CA-74CF-4E50-93C6-F12482FB7914}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\Helper\win64\nwjc.exe No File FirewallRules: [{97C847C8-144F-483B-B69B-18ABAD01760C}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\Helper\win64\nwjc.exe No File FirewallRules: [{FA0F071C-7394-4121-9485-DD323079D5C4}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\Helper\win64\BigScreen.exe No File FirewallRules: [{D96B82AE-EFA2-4C13-8402-5CDFD19CE2F6}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\Helper\win64\BigScreen.exe No File FirewallRules: [{6AD3F541-5900-421E-B0CA-4E5AEE53C4C6}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\CoherentUI_Host\windows\CoherentUI_Host.exe No File FirewallRules: [{176BBDA1-8E07-4EBE-8C96-3AF21D589C35}] => (Allow) C:\Program Files\Oculus\Software\Software\bigscreen-bigscreen\Bigscreen\Bigscreen_Data\CoherentUI_Host\windows\CoherentUI_Host.exe No File FirewallRules: [{71E8C253-C6E3-4600-ABA5-499E8605EC71}] => (Allow) C:\Program Files\Oculus\Software\Software\ready-at-dawn-r14-multiplayer\bin\win7\BsSndRpt64.exe No File FirewallRules: [{63365E8E-1352-4DDC-A4F9-B1FB0321FC11}] => (Allow) C:\Program Files\Oculus\Software\Software\ready-at-dawn-r14-multiplayer\bin\win7\BsSndRpt64.exe No File FirewallRules: [{F6F68D16-115E-4521-AD58-7F018CB0775F}] => (Allow) C:\Program Files\Oculus\Software\Software\ready-at-dawn-r14-multiplayer\bin\win7\EchoArena.exe No File FirewallRules: [{7E23F0F4-07F7-487D-B152-EC66752455B2}] => (Allow) C:\Program Files\Oculus\Software\Software\ready-at-dawn-r14-multiplayer\bin\win7\EchoArena.exe No File FirewallRules: [{003924CB-3EBE-4F36-B890-FAA11B5A3C58}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\bin\OculusMedium.exe No File FirewallRules: [{9F9FACD1-FC74-4444-92E0-D148E4C2EC6D}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\bin\OculusMedium.exe No File FirewallRules: [{8A286587-F2FA-4973-9598-A20684A5DD24}] => (Allow) C:\Program Files\Oculus\Software\Software\facebook-vr-facebookvr\FacebookSpaces.exe No File FirewallRules: [{B2353093-FFC2-4EC4-AEFF-36D589F6C4BB}] => (Allow) C:\Program Files\Oculus\Software\Software\facebook-vr-facebookvr\FacebookSpaces.exe No File FirewallRules: [{F7567361-4B56-4E7F-8E23-6716F7F054CC}] => (Allow) C:\Program Files\Oculus\Software\Software\facebook-vr-facebookvr\FacebookSpaces_Data\StreamingAssets\EndPointController.exe No File FirewallRules: [{DB126F09-42AF-4A49-8B2D-276F49B576EB}] => (Allow) C:\Program Files\Oculus\Software\Software\facebook-vr-facebookvr\FacebookSpaces_Data\StreamingAssets\EndPointController.exe No File FirewallRules: [{24EBDE4F-05B7-4161-9B6D-357E5FB200A9}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-dead-and-buried\DeadAndBuried\DeadAndBuried.exe No File FirewallRules: [{19C464A9-3976-4D57-8A06-0947A188599A}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-dead-and-buried\DeadAndBuried\DeadAndBuried.exe No File FirewallRules: [{25EB664A-D4D7-456B-91B4-D9B4E119F4D1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\win32\vrstartup.exe () FirewallRules: [{97410209-ED16-41BB-99BD-F37A3DB62A61}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\bin\win32\vrstartup.exe () FirewallRules: [{10B36F0E-BA6E-40F4-93CC-66ECC7426749}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\tools\steamvr_environments\game\bin\win64\steamtours.exe () FirewallRules: [{ECA8142C-2031-4529-848A-BC2BA32EF129}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\tools\steamvr_environments\game\bin\win64\steamtours.exe () FirewallRules: [{5119CCDB-9BA3-4E2F-BB45-8E124FE44E81}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\tools\steamvr_environments\game\bin\win64\steamtourscfg.exe () FirewallRules: [{A0C47712-C6F1-478A-A5C9-F2A1222FBCCC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\SteamVR\tools\steamvr_environments\game\bin\win64\steamtourscfg.exe () FirewallRules: [{045A6A13-26B7-407A-93C3-3D1390093FCE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rFactor 2\Launcher\Launch rFactor.exe () FirewallRules: [{7E9EBEFD-D0A1-49BE-8EFD-72059ADA72BF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rFactor 2\Launcher\Launch rFactor.exe () FirewallRules: [TCP Query User{6AC2C07F-1DF2-4C8C-A860-B4116538DA61}C:\users\kurt\downloads\iracingbrowserapps\server.exe] => (Allow) C:\users\kurt\downloads\iracingbrowserapps\server.exe No File FirewallRules: [UDP Query User{889A572B-3719-4390-AEC6-9C9CDEEAEEC1}C:\users\kurt\downloads\iracingbrowserapps\server.exe] => (Allow) C:\users\kurt\downloads\iracingbrowserapps\server.exe No File FirewallRules: [TCP Query User{097110F7-5FE9-4858-816E-3959823D3CD7}C:\users\kurt\downloads\iracingbrowserapps\chat.exe] => (Allow) C:\users\kurt\downloads\iracingbrowserapps\chat.exe No File FirewallRules: [UDP Query User{AE8632BA-3AE7-417E-8256-43A9670F4FFF}C:\users\kurt\downloads\iracingbrowserapps\chat.exe] => (Allow) C:\users\kurt\downloads\iracingbrowserapps\chat.exe No File FirewallRules: [TCP Query User{CFA3FB8E-4495-4F61-9067-47A5C1A64263}C:\users\kurt\desktop\iracingbrowserapps\server.exe] => (Allow) C:\users\kurt\desktop\iracingbrowserapps\server.exe No File FirewallRules: [UDP Query User{94C41EE6-725C-41AB-8A1A-4B6581DB1625}C:\users\kurt\desktop\iracingbrowserapps\server.exe] => (Allow) C:\users\kurt\desktop\iracingbrowserapps\server.exe No File FirewallRules: [TCP Query User{40AFD6B7-297B-4B70-B255-2766D29700AE}C:\program files\eagle dynamics\dcs world\bin\dcs_updater.exe] => (Allow) C:\program files\eagle dynamics\dcs world\bin\dcs_updater.exe No File FirewallRules: [UDP Query User{1D59D3DC-63E3-42DC-AC1F-8414468ADCB5}C:\program files\eagle dynamics\dcs world\bin\dcs_updater.exe] => (Allow) C:\program files\eagle dynamics\dcs world\bin\dcs_updater.exe No File FirewallRules: [TCP Query User{A67D6705-32B7-4390-AC5D-4EE543B4F10B}C:\program files\eagle dynamics\dcs world\bin\dcs.exe] => (Allow) C:\program files\eagle dynamics\dcs world\bin\dcs.exe No File FirewallRules: [UDP Query User{4036BD25-CD49-437C-A59D-C90EACF2B8DE}C:\program files\eagle dynamics\dcs world\bin\dcs.exe] => (Allow) C:\program files\eagle dynamics\dcs world\bin\dcs.exe No File FirewallRules: [{D7ED2A98-9EF9-4D96-B917-9FD81828FCC0}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File FirewallRules: [{85CCC196-57EA-4B02-B2C3-7562E8B20AB1}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe No File FirewallRules: [{CB10FE43-5710-466B-A5F6-A585017FBFC4}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games) FirewallRules: [{B936138A-81FC-4B97-BAB0-36DD064CA04B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe (Rockstar Games) FirewallRules: [TCP Query User{698BC006-25E7-4835-83BF-C8DEC3F1C5FF}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games) FirewallRules: [UDP Query User{40DD41BA-54D2-4B5E-82B1-8D9B73D1B78A}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games) FirewallRules: [{00CBCED8-9E8E-4961-95AF-F7EACDA81F6B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation) FirewallRules: [{A06302AA-1206-46E5-833E-8F5D608FA2D9}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation) FirewallRules: [TCP Query User{B9EAE488-A82C-43DE-BE41-774BAD0E9D9D}C:\program files (x86)\soundwire server\soundwireserver.exe] => (Allow) C:\program files (x86)\soundwire server\soundwireserver.exe No File FirewallRules: [UDP Query User{5584B0A7-561F-488C-8809-E81C1358A55F}C:\program files (x86)\soundwire server\soundwireserver.exe] => (Allow) C:\program files (x86)\soundwire server\soundwireserver.exe No File FirewallRules: [{82F5F6AF-EC55-410B-9E60-4F33D3B47CCA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) FirewallRules: [{201D8067-8BB9-409D-995D-54E15AC2729C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) FirewallRules: [{6C982285-1F6C-40F9-9913-E4B2F6710DDF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH) FirewallRules: [{60D7EDFC-8A40-46C1-96FF-AB487A33968B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH) FirewallRules: [{B69FEA50-E5DF-4A44-9E79-5F0839FE6D6F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) FirewallRules: [{4E9D3C6D-D78E-4C68-A90E-772B9D2878E5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) FirewallRules: [{6EE4EB05-268E-4AC1-9A6F-AC7D630C2B2B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) FirewallRules: [{D912D3CA-A9E3-428F-A108-110629A67DAC}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) FirewallRules: [{17FAD6A0-E04C-4245-A0EE-5EA6684686B0}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corporation) FirewallRules: [{BBDCE2E1-1700-4EF3-BA5F-9449EC52314C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve Corporation) FirewallRules: [{CD40F335-27D2-438B-9950-C80CB6B7956E}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation) FirewallRules: [{6E3FE81F-5083-42DB-BF98-CC7CCA1ECFED}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe (Microsoft Corporation) FirewallRules: [{F2F2E492-6E8C-4126-B0AF-E9F64F977359}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe (Microsoft Corporation) FirewallRules: [{24E806E7-90F3-4E2F-B08E-A4701D71C8E2}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\71.0.3578.15\remoting_host.exe (Google Inc.) FirewallRules: [TCP Query User{BDC8DDE8-8857-4384-AD0B-EF101A63FB22}C:\users\kurt\appdata\local\sodaplayer\app-1.4.2\soda player.exe] => (Allow) C:\users\kurt\appdata\local\sodaplayer\app-1.4.2\soda player.exe (Soda Player) FirewallRules: [UDP Query User{29D0D158-C536-4FCD-B8E6-1F1AD329C1F3}C:\users\kurt\appdata\local\sodaplayer\app-1.4.2\soda player.exe] => (Allow) C:\users\kurt\appdata\local\sodaplayer\app-1.4.2\soda player.exe (Soda Player) FirewallRules: [{AA3B4038-5BF0-40BC-A28E-CA9E956787DD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LIV\LIV.App.exe (LIV Inc.) FirewallRules: [{A18F898E-AF6D-457A-963A-BF3E867090BE}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\LIV\LIV.App.exe (LIV Inc.) FirewallRules: [{DA85442A-9C8F-4089-83E0-F1B557A92000}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) FirewallRules: [{8887874B-6D91-4D30-9CBB-A4BE2829B485}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) FirewallRules: [{11948F3F-4A87-423A-9F17-A5600EB4BE99}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation) FirewallRules: [{D8A1CFC5-CF7D-48D2-8941-307FD45224DA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation) FirewallRules: [{B0BCDFD5-B118-4696-99E4-3E3747CD9187}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe (Psyonix, Inc) FirewallRules: [{C012C06E-495B-4829-9972-C2E416B7EF11}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe (Psyonix, Inc) FirewallRules: [{3A8A11CC-2867-427D-B4D7-A752E72EED03}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) FirewallRules: [{1746D1E2-4967-4D10-9AF0-BC956128F38D}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\medium\bin\OculusMedium.exe No File FirewallRules: [{8B704641-976F-4A01-89C5-B631EACEB6E2}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\medium\bin\OculusMedium.exe No File FirewallRules: [{2F5A4843-DC84-40B0-A974-5DFEDBEA4BDF}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\bin\python35\python.exe No File FirewallRules: [{FCDAC947-D90F-4ECB-B302-77A90DB2B768}] => (Allow) C:\Program Files\Oculus\Software\Software\oculus-oculus-medium-retail\bin\python35\python.exe No File FirewallRules: [{9B419521-8F1F-4234-BF48-357233915673}] => (Allow) %systemroot%\system32\alg.exe (Microsoft Corporation) FirewallRules: [{0C397272-A8D3-4E4A-B84A-DEA7A45FC674}] => (Allow) %systemroot%\system32\alg.exe (Microsoft Corporation) FirewallRules: [{4F6EA576-5188-42BC-9149-D6C10135706E}] => (Allow) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe () FirewallRules: [{981F544B-94C0-4D80-979B-B45B37290219}] => (Allow) C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe () FirewallRules: [{9E4C0B5D-1F9E-4233-8F94-A3E6384DFD53}] => (Allow) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe (Facebook Technologies, LLC) FirewallRules: [{DA319245-2D79-42CF-983B-7922C43A9247}] => (Allow) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe (Facebook Technologies, LLC) FirewallRules: [{EF6A93B9-B7A8-4CD0-81BC-7B20F3FB3F6A}] => (Allow) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe (Facebook Technologies, LLC) FirewallRules: [{CC455710-1423-4D01-83E3-DD7BAC750F28}] => (Allow) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe (Facebook Technologies, LLC) FirewallRules: [{89B340CC-8EA6-4A4A-A027-AF5CFE108EE4}] => (Allow) C:\Program Files\Oculus\Support\oculus-dash\dash\bin\OculusDash.exe () FirewallRules: [{F2AE09B8-734A-4A6E-A6C1-8D014215D270}] => (Allow) C:\Program Files\Oculus\Support\oculus-dash\dash\bin\OculusDash.exe () FirewallRules: [{3F66C62C-BB81-4E9D-9F8F-C06FBA239101}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe () FirewallRules: [{CB461C26-A462-482F-8499-4447B790FDC4}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2.exe () FirewallRules: [{64FB3D18-C597-48E3-A7C5-D14985EA1443}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2\Binaries\Win64\Home2-Win64-Shipping.exe () FirewallRules: [{A4390862-E96E-43F0-B6F5-5742B1BC8D10}] => (Allow) C:\Program Files\Oculus\Support\oculus-worlds\Home2\Binaries\Win64\Home2-Win64-Shipping.exe () FirewallRules: [{85BFFEF9-870A-4854-BABE-E973F58C4108}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) FirewallRules: [{48380763-B077-4EBC-932D-7715E469B500}] => (Allow) C:\Program Files\Oculus\Support\oculus-client\OculusClient.exe (Oculus VR, LLC) ==================== Restore Points ========================= 15-01-2019 17:34:20 PC Decrapifier Restore Point ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/15/2019 07:07:38 PM) (Source: tmpid) (EventID: 2) (User: ) Description: CDIEffectDriver::CDIEffectDriver() CoInitialize() FAILED, GLE:0, proc:C:\Users\Kurt\Documents\irFFB.exe Error: (01/15/2019 07:00:56 PM) (Source: tmpid) (EventID: 2) (User: ) Description: CDIEffectDriver::CDIEffectDriver() CoInitialize() FAILED, GLE:0, proc:C:\Users\Kurt\Documents\irFFB.exe Error: (01/15/2019 06:59:33 PM) (Source: OVRServiceLauncher) (EventID: 0) (User: ) Description: Event-ID 0 Error: (01/15/2019 06:56:47 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: iRacingSim64DX11.exe, version: 2.30.3.17, time stamp: 0x5c364a33 Faulting module name: easyanticheat_x64.dll_unloaded, version: 2.0.0.0, time stamp: 0x5bbf023b Exception code: 0xc0000005 Fault offset: 0x00000000000365cc Faulting process id: 0xf84 Faulting application start time: 0x01d4ad3608a1b41f Faulting application path: C:\Program Files (x86)\iRacing\iRacingSim64DX11.exe Faulting module path: easyanticheat_x64.dll Report Id: 71d6231c-70c9-4849-8874-72423266e436 Faulting package full name: Faulting package-relative application ID: Error: (01/15/2019 06:54:47 PM) (Source: tmpid) (EventID: 2) (User: ) Description: CDIEffectDriver::CDIEffectDriver() CoInitialize() FAILED, GLE:0, proc:C:\Program Files (x86)\iRacing\iRacingSim64DX11.exe Error: (01/15/2019 06:36:44 PM) (Source: tmpid) (EventID: 2) (User: ) Description: CDIEffectDriver::CDIEffectDriver() CoInitialize() FAILED, GLE:0, proc:C:\Users\Kurt\Documents\irFFB.exe Error: (01/15/2019 06:34:54 PM) (Source: OVRServiceLauncher) (EventID: 0) (User: ) Description: Event-ID 0 Error: (01/15/2019 05:48:30 PM) (Source: SideBySide) (EventID: 35) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1. Component identity found in manifest does not match the identity of the component requested. Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0". Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0". Please use sxstrace.exe for detailed diagnosis. System errors: ============= Error: (01/15/2019 07:05:20 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-J7JIURT) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user DESKTOP-J7JIURT\Kurt SID (S-1-5-21-1188590385-209233840-2562061582-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/15/2019 07:01:51 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID Windows.SecurityCenter.WscBrokerManager and APPID Unavailable to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/15/2019 07:01:51 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID Windows.SecurityCenter.WscDataProtection and APPID Unavailable to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/15/2019 06:59:53 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/15/2019 06:59:53 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (01/15/2019 06:59:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Apple Mobile Device Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (01/15/2019 06:59:33 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (60000 milliseconds) while waiting for the Apple Mobile Device Service service to connect. Error: (01/15/2019 06:59:30 PM) (Source: Microsoft-Windows-Directory-Services-SAM) (EventID: 16953) (User: NT AUTHORITY) Description: The password notification DLL C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter failed to load with error 126. Please verify that the notification DLL path defined in the registry, HKLM\System\CurrentControlSet\Control\Lsa\Notification Packages, refers to a correct and absolute path (<drive>:\<path>\<filename>.<ext>) and not a relative or invalid path. If the DLL path is correct, please validate that any supporting files are located in the same directory, and that the system account has read access to both the DLL path and any supporting files. Contact the provider of the notification DLL for additional support. Further details can be found on the web at http://go.microsoft.com/fwlink/?LinkId=245898. Windows Defender: =================================== Date: 2019-01-15 03:37:29.164 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {93722089-D99C-4CE9-8D39-6D2FD4BD7007} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-01-09 02:31:13.333 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {86143803-E126-4758-BBE1-7829AC508D31} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-01-08 01:40:23.410 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {E5BB0AEB-8734-4275-BD63-26145DF9D75D} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-01-07 12:47:52.332 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {DA493089-D90A-4A26-BB8B-215565B7FABA} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-01-05 04:11:01.730 Description: Windows Defender Antivirus scan has been stopped before completion. Scan ID: {2FF2EA36-FFD2-4C89-A8D9-3CDD33121E74} Scan Type: Antimalware Scan Parameters: Quick Scan Date: 2019-01-07 02:56:06.553 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.283.2389.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.15500.2 Error code: 0x80240438 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. Date: 2019-01-04 12:10:57.378 Description: Windows Defender Antivirus Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions. Date: 2018-12-27 11:21:49.256 Description: Windows Defender Antivirus has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.283.1625.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.15500.2 Error code: 0x80240016 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support. CodeIntegrity: =================================== Date: 2019-01-15 18:57:40.166 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-01-15 18:57:39.836 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-01-15 18:57:32.670 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-01-15 18:57:32.662 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2019-01-15 17:52:47.759 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Microsoft signing level requirements. Date: 2018-11-07 10:37:32.769 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-11-07 10:37:32.768 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. Date: 2018-11-07 10:35:43.641 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-6700 CPU @ 3.40GHz Percentage of memory in use: 33% Total physical RAM: 16322.83 MB Available physical RAM: 10835.29 MB Total Virtual: 18754.83 MB Available Virtual: 11163.94 MB ==================== Drives ================================ Drive 😄 (OS) (Fixed) (Total:1849.43 GB) (Free:1515.45 GB) NTFS \\?\Volume{cb2556f6-1112-4f8a-8c83-ce733d395eb0}\ (WINRETOOLS) (Fixed) (Total:0.44 GB) (Free:0.05 GB) NTFS \\?\Volume{3cac9fc6-4e87-456e-9acc-66d9e886539c}\ (Image) (Fixed) (Total:12.53 GB) (Free:0.63 GB) NTFS \\?\Volume{5e398e8d-ff2e-4fd5-a5cf-b0924cef18e4}\ (ESP) (Fixed) (Total:0.48 GB) (Free:0.45 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 1863 GB) (Disk ID: 8FE513EB) Partition: GPT. ==================== End of Addition.txt ============================
  18. I have come across a program titled wondershare that I deleted a few months ago which still shows some signs of being on my PC. Under add or remove programs it doesn't show up, but under a 3rd party program, I use titled PC Decrapifier it appears as a startup program. I found a thread in this forum with a practically identical issue to me. This user's issues seemed to be corrected by a special log created by one of the Mods/Admins. Currently, I Have installed and ran FRST below is my log from FRST.txt I also verified that wondershare is not in my Common Files Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.01.2019 01 Ran by Kurt (administrator) on DESKTOP-J7JIURT (15-01-2019 19:14:43) Running from C:\Users\Kurt\Desktop\PC Management Loaded Profiles: Kurt (Available Profiles: Kurt & Kurt Q & OVRLibraryService) Platform: Windows 10 Home Version 1803 17134.523 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\71.0.3578.15\remoting_host.exe (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) C:\Program Files (x86)\iRacing\iRacingService64.exe (McAfee, Inc.) C:\Program Files\McAfee\WebAdvisor\servicehost.exe () C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe (Thrustmaster®) C:\Program Files\Thrustmaster\FFB Racing wheel\drivers\amd64\tmInstall.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Ready Mode Technology\IRMTService.exe (Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1812.3-0\MsMpEng.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\71.0.3578.15\remoting_host.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1812.3-0\NisSrv.exe (McAfee, Inc.) C:\Program Files\McAfee\WebAdvisor\uihost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Facebook Technologies, LLC) C:\Program Files\Oculus\Support\oculus-runtime\OVRServer_x64.exe () C:\Program Files\Oculus\Support\oculus-runtime\OVRRedir.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18102.12011.0_x64__8wekyb3d8bbwe\Video.UI.exe () C:\Program Files (x86)\Realtek\Realtek Bluetooth\SkypePlugin.exe (Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.10314.31700.1000_x64__8wekyb3d8bbwe\Office16\OfficeHubTaskHost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (CyberLink) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\Power2Go8\CLMLSvc_P2G8.exe () C:\Users\Kurt\Documents\irFFB.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe (PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1466\DSAPI.exe (Dell Inc.) C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe (PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1466\pcdrwi.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe (Jason York) C:\Users\Kurt\AppData\Local\Temp\pc-decrapifier.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Dell) C:\Program Files\Dell\Dell Product Registration\PRSvc.exe (Microsoft Corporation) C:\Program Files\rempl\sedsvc.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Users\Kurt\Documents\irFFB.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-11] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-08-03] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_MAXX6] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-03] (Realtek Semiconductor) HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [231640 2016-05-13] (Realtek Semiconductor Corporation) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321096 2017-08-18] (Intel Corporation) HKLM\...\Run: [WavesSvc] => C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe [611248 2015-04-19] (Waves Audio Ltd.) HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle Corporation) HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-11] (Microsoft Corporation) HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\Run: [irFFB] => C:\Users\Kurt\Documents\irFFB.exe [166912 2018-06-03] () HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\Run: [Spotify] => C:\Users\Kurt\AppData\Roaming\Spotify\Spotify.exe [25972968 2019-01-01] (Spotify Ltd) HKU\S-1-5-21-1188590385-209233840-2562061582-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\Plane9.scr HKLM\...\Drivers32: [vidc.i420] => c:\windows\system32\lvcod64.dll [175392 2012-10-26] (Logitech Inc.) HKLM\...\Drivers32: [VIDC.WVC1] => c:\windows\system32\d3dgeardecoder64.dll [165320 2018-03-26] (D3DGear Technologies.) HKLM\...\Drivers32: [VIDC.WMV3] => c:\windows\system32\d3dgeardecoder64.dll [165320 2018-03-26] (D3DGear Technologies.) HKLM\...\Drivers32: [VIDC.MJPG] => c:\windows\system32\d3dgeardecoder64.dll [165320 2018-03-26] (D3DGear Technologies.) HKLM\...\Drivers32: [VIDC.M4S2] => c:\windows\system32\d3dgeardecoder64.dll [165320 2018-03-26] (D3DGear Technologies.) HKLM\...\Drivers32: [VIDC.FVFW] => c:\windows\system32\d3dgeardecoder64.dll [165320 2018-03-26] (D3DGear Technologies.) HKLM\...\Drivers32: [VIDC.FFVH] => c:\windows\system32\d3dgeardecoder64.dll [165320 2018-03-26] (D3DGear Technologies.) HKLM\...\Drivers32: [VIDC.H264] => c:\windows\system32\d3dgeardecoder64.dll [165320 2018-03-26] (D3DGear Technologies.) HKLM\...\Drivers32: [VIDC.RTV1] => c:\windows\system32\rtvcvfw64.dll [246272 2012-09-28] () HKLM\...\Drivers32: [VIDC.MP4V] => c:\windows\system32\d3dgeardecoder64.dll [165320 2018-03-26] (D3DGear Technologies.) HKLM\...\Drivers32: [MSVideo] => c:\windows\system32\vfwwdm32.dll [67072 2018-04-11] (Microsoft Corporation) HKLM\...\Drivers32-x32: [vidc.i420] => C:\Windows\SysWOW64\lvcodec2.dll [305000 2012-10-26] (Logitech Inc.) HKLM\...\Drivers32-x32: [VIDC.WVC1] => c:\program files (x86)\iracing\d3dgeardecoder.dll [143968 2018-12-04] (D3DGear Technologies.) HKLM\...\Drivers32-x32: [VIDC.WMV3] => c:\program files (x86)\iracing\d3dgeardecoder.dll [143968 2018-12-04] (D3DGear Technologies.) HKLM\...\Drivers32-x32: [VIDC.MJPG] => c:\program files (x86)\iracing\d3dgeardecoder.dll [143968 2018-12-04] (D3DGear Technologies.) HKLM\...\Drivers32-x32: [VIDC.M4S2] => c:\program files (x86)\iracing\d3dgeardecoder.dll [143968 2018-12-04] (D3DGear Technologies.) HKLM\...\Drivers32-x32: [VIDC.FVFW] => c:\program files (x86)\iracing\d3dgeardecoder.dll [143968 2018-12-04] (D3DGear Technologies.) HKLM\...\Drivers32-x32: [VIDC.FFVH] => c:\program files (x86)\iracing\d3dgeardecoder.dll [143968 2018-12-04] (D3DGear Technologies.) HKLM\...\Drivers32-x32: [VIDC.H264] => c:\program files (x86)\iracing\d3dgeardecoder.dll [143968 2018-12-04] (D3DGear Technologies.) HKLM\...\Drivers32-x32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () HKLM\...\Drivers32-x32: [VIDC.MP4V] => c:\program files (x86)\iracing\d3dgeardecoder.dll [143968 2018-12-04] (D3DGear Technologies.) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2018-12-17] (Google Inc.) Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2018-09-12] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.766\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{204ba5f7-b809-453c-ad5d-fbb9650fb68e}: [DhcpNameServer] 209.222.18.222 209.222.18.218 Tcpip\..\Interfaces\{a57fe5aa-a2fc-451f-81ef-e07bbde6d3cc}: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{ccbf3d84-af10-46c5-8d4f-cf943a5a89d9}: [DhcpNameServer] 162.150.8.37 162.150.21.37 Tcpip\..\Interfaces\{f3d56167-4d80-4349-a4b4-6f75e922456b}: [DhcpNameServer] 75.75.75.75 75.75.76.76 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = HKU\S-1-5-21-1188590385-209233840-2562061582-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell15.msn.com/?pc=DCTE SearchScopes: HKLM -> DefaultScope {444B7183-363F-4EE0-8083-2643757ABB85} URL = SearchScopes: HKLM-x32 -> DefaultScope {444B7183-363F-4EE0-8083-2643757ABB85} URL = SearchScopes: HKU\S-1-5-21-1188590385-209233840-2562061582-1001 -> {14134E89-AFA2-4FCE-924C-DF6145355AB5} URL = hxxps://search.yahoo.com/search?p={searchTerms}&intl=us&fr=yset_ie_syc_oracle&type=orcl_default&partnerexternal-oracle=external-oracle BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2019-01-12] (Microsoft Corporation) BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2018-12-16] (McAfee, Inc.) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-12-02] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-01-15] (Oracle Corporation) BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2018-12-16] (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-01-15] (Oracle Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-12] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-12] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-12] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2019-01-12] (Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll No File Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll No File StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF DefaultProfile: 6mpxvezx.default FF DefaultProfile: rsmyz2py.default FF ProfilePath: C:\Users\Kurt\AppData\Roaming\Zotero\Zotero\Profiles\6mpxvezx.default [2018-05-06] FF Extension: (No Name) - C:\Program Files (x86)\Zotero\extensions\zoteroOpenOfficeIntegration@zotero.org [not found] FF Extension: (No Name) - C:\Program Files (x86)\Zotero\extensions\zoteroWinWordIntegration@zotero.org [not found] FF ProfilePath: C:\Users\Kurt\AppData\Roaming\Mozilla\Firefox\Profiles\rsmyz2py.default [2019-01-07] FF Extension: (No Name) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [not found] FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2018-12-16] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi FF HKU\S-1-5-21-1188590385-209233840-2562061582-1001\...\Firefox\Extensions: [acewebextension_unlisted@acestream.org] - C:\Users\Kurt\AppData\Roaming\ACEStream\extensions\awe\firefox\acewebextension_unlisted.xpi => not found FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_114.dll [2019-01-08] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_114.dll [2019-01-08] () FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-01-15] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-01-15] (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2019-01-12] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-09-11] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File] FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-11-29] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-11-29] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://members.iracing.com/membersite/ CHR StartupUrls: Default -> "hxxps://www.youtube.com/","hxxps://www.google.com/","hxxp://uwp.edu/","hxxps://www.uwp.edu/","hxxps://uwp.edu","hxxp://uwp.edu/currentstudent/","hxxp://www.google.com/" CHR NewTab: Default -> Not-active:"chrome-extension://mfgdmpfihlmdekaclngibpjhdebndhdj/newtab.html" CHR Profile: C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default [2019-01-15] CHR Extension: (YouTube) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\adnlfjpnmidfimlkaohpidplnoimahfh [2018-03-02] CHR Extension: (Docs) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14] CHR Extension: (Google Drive) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-13] CHR Extension: (YouTube) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-13] CHR Extension: (GeoGebra Classic) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2017-09-14] CHR Extension: (Form Filler) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnjjngeaknajbdcgpfkgnonkmififhfo [2018-04-09] CHR Extension: (Dark Reader) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\eimadpbcbfnmbkopoojfekhnkhdbieeh [2019-01-09] CHR Extension: (Floating Player) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekajjllcmeckibblgckgoceinmmgnfop [2018-10-25] CHR Extension: (Sheets) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14] CHR Extension: (Gyazo) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdaeeijbbijklfcpahbghahojgfgebo [2018-05-25] CHR Extension: (JRT Timing4) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\geffekafihibcfgilfjabnbpefajijej [2018-03-01] CHR Extension: (Google Docs Offline) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-18] CHR Extension: (AdBlock) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-12-11] CHR Extension: (Video Adblocker for Youtube™ Extension) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\hflefjhkfeiaignkclmphmokmmbhbhik [2018-08-10] CHR Extension: (Picture-in-Picture Extension (by Google)) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkgfoiooedgoejojocmhlaklaeopbecg [2019-01-13] CHR Extension: (JRT Compteur) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnfgkbkdgdcojpncgpbpmehhcpkgcndk [2018-03-02] CHR Extension: (JRT Timing) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\iildogoiieiomhkamkclacafknmgjnge [2018-03-02] CHR Extension: (JRT Dashboard) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcjdaikbfehoagfpllmjifiibklfgdc [2018-03-02] CHR Extension: (Chrome Remote Desktop) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\inomeogfingihgjfjlpeplalcfajhgai [2018-09-23] CHR Extension: (Floating for YouTube™) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjphmlaoffndcnecccgemfdaaoighkel [2018-03-11] CHR Extension: (Grammarly for Chrome) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2019-01-08] CHR Extension: (Allow Select And Copy) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\lamaakaemgdclpnfbofmhpkanfnojjch [2018-10-08] CHR Extension: (Humble New Tab Page) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfgdmpfihlmdekaclngibpjhdebndhdj [2018-12-02] CHR Extension: (Chrome Web Store Payments) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04] CHR Extension: (VIPBox) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifmfjojonabdfdbahgjkhhoneinkkd [2018-03-02] CHR Extension: (TeamViewer) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\oooiobdokpcfdlahlmcddobejikcmkfo [2018-11-01] CHR Extension: (iRacing.com™ Race Guide) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\phiocplhljmeipikdanklondaeanchip [2018-03-02] CHR Extension: (Gmail) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-08-13] CHR Extension: (Chrome Media Router) - C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-19] CHR Profile: C:\Users\Kurt\AppData\Local\Google\Chrome\User Data\System Profile [2018-03-16] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-1188590385-209233840-2562061582-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mjbepbhonbojpoaenhckjocchgfiaofo] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-07-05] (Apple Inc.) R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [125144 2016-02-15] (Realtek Semiconductor Corp.) R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\71.0.3578.15\remoting_host.exe [73048 2018-10-18] (Google Inc.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [9619616 2019-01-02] (Microsoft Corporation) R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [209392 2018-10-22] (Dell Inc.) R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3347440 2018-10-22] (Dell Inc.) R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [218096 2018-10-22] (Dell Inc.) R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1466\DSAPI.exe [1035072 2019-01-09] (PC-Doctor, Inc.) R2 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [40976 2017-09-18] (Dell Inc.) S2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2572024 2016-12-13] (Dell Inc.) R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237016 2018-03-27] (Dell Inc.) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [526888 2017-10-09] (EasyAntiCheat Ltd) S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2413752 2017-08-18] (Intel Corporation) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2017-08-18] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-10-11] (Intel(R) Corporation) S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed] S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-10-11] (Intel(R) Corporation) R2 iRacingService; C:\Program Files (x86)\iRacing\iRacingService64.exe [1187744 2019-01-10] (iRacing.com Motorsport Simulations, LLC Bedford, MA 01730) R2 IRMTService; c:\Program Files\Intel\Intel(R) Ready Mode Technology\IRMTService.exe [182336 2015-09-10] (Intel Corporation) R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [213648 2017-11-08] (Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes) R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [690248 2018-12-16] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.766\McCHSvc.exe [405392 2018-07-11] (McAfee, Inc.) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [786800 2018-11-16] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [786800 2018-11-16] (NVIDIA Corporation) S3 OVRLibraryService; C:\Program Files\Oculus\Support\oculus-librarian\OVRLibraryService.exe [142776 2019-01-12] (Facebook Technologies, LLC) R2 OVRService; C:\Program Files\Oculus\Support\oculus-runtime\OVRServiceLauncher.exe [1681848 2019-01-12] (Facebook Technologies, LLC) R2 Product Registration; C:\Program Files\Dell\Dell Product Registration\PRSvc.exe [47144 2017-04-06] (Dell) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2014-04-14] () R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312056 2015-08-03] (Realtek Semiconductor) S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] () R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [39384 2018-12-12] (Dell Inc.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11644144 2018-07-23] (TeamViewer GmbH) R2 tmInstall; C:\Program Files\Thrustmaster\FFB Racing wheel\drivers\amd64\tmInstall.EXE [128640 2017-11-17] (Thrustmaster®) R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [563456 2015-01-19] (Waves Audio Ltd.) R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\NisSrv.exe [3880120 2018-12-10] (Microsoft Corporation) R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MsMpEng.exe [114208 2018-12-10] (Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 442652BC; C:\WINDOWS\system32\drivers\442652BC.sys [255928 2019-01-15] (Malwarebytes) R3 BthAudioHF; C:\WINDOWS\system32\drivers\RtkHfp.sys [123944 2016-08-25] (Realtek Semiconductor Corporation) R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink) R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [36400 2018-10-20] (Dell Inc.) S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2018-05-08] (Dell Computer Corporation) S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.) S3 DroidCam; C:\WINDOWS\system32\DRIVERS\droidcam.sys [33592 2015-05-23] (Dev47Apps) S3 DroidCamVideo; C:\WINDOWS\system32\DRIVERS\droidcamvideo.sys [230712 2015-05-23] (Windows (R) Win 7 DDK provider) S3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-07-28] (Disc Soft Ltd) S3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-07-28] (Disc Soft Ltd) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77432 2017-11-29] () S3 FanatecWheelFilterUsb; C:\WINDOWS\System32\drivers\FWFilterUsb.sys [81032 2016-10-21] (Endor AG) S3 FWVirtualInputDevice; C:\WINDOWS\System32\drivers\FWVirtualInputDevice.sys [35464 2016-10-21] (Endor AG) S3 HidGuardian; C:\WINDOWS\System32\drivers\HidGuardian.sys [26736 2017-04-17] (Benjamin Höglinger-Stelzer) S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70664 2017-08-18] (Intel Corporation) R3 IntelReadyModeDriver; C:\WINDOWS\System32\drivers\IntelReadyModeDriver.sys [33512 2015-09-10] (Intel Corporation) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [193968 2019-01-15] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [110016 2019-01-15] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [46008 2019-01-15] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253880 2019-01-15] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [94144 2019-01-15] (Malwarebytes) R3 mfesapsn; C:\Program Files\McAfee\WebAdvisor\mfesapsn.sys [111976 2018-12-16] (McAfee, Inc.) S3 mt7612US; C:\WINDOWS\System32\drivers\mt7612US.sys [377864 2015-12-09] (MediaTek Inc.) R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_9db4450b8107f59a\nvlddmkm.sys [20420352 2018-11-30] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2018-10-25] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [70024 2018-10-01] (NVIDIA Corporation) R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [74576 2018-10-01] (NVIDIA Corporation) R3 OCULUSVRHEADSET; C:\WINDOWS\system32\DRIVERS\OCULUS119B.sys [1887232 2019-01-12] (OCULUS) R3 Oculus_ViGEmBus; C:\WINDOWS\System32\drivers\Oculus_ViGEmBus.sys [32856 2019-01-12] (Facebook Inc.) R3 OCUSBVID; C:\WINDOWS\System32\drivers\ocusbvid111.sys [69176 2019-01-12] (Oculus VR, LLC) R3 RtkBtFilter; C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys [765936 2017-11-27] (Realtek Semiconductor Corporation) R3 RTWlanE; C:\WINDOWS\System32\drivers\rtwlane.sys [7895400 2017-11-07] (Realtek Semiconductor Corporation ) R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions) S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.) S3 tap-tb-0901; C:\WINDOWS\System32\drivers\tap-tb-0901.sys [38656 2018-05-16] (The OpenVPN Project) R3 tmhidusb; C:\WINDOWS\system32\DRIVERS\tmhidusb.sys [323200 2017-11-17] (Thrustmaster) S3 tmwbulk; C:\WINDOWS\System32\Drivers\tmwbulk.sys [245376 2017-11-24] (© Guillemot R&D, 2017. All rights reserved.) R3 vjoy; C:\WINDOWS\System32\drivers\vjoy.sys [57976 2017-04-06] (Shaul Eizikovich) S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46680 2018-12-10] (Microsoft Corporation) R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [330936 2018-12-10] (Microsoft Corporation) R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [62136 2018-12-10] (Microsoft Corporation) S3 XSplit_Dummy; C:\WINDOWS\system32\drivers\xspltspk.sys [26200 2016-06-15] (SplitmediaLabs Limited) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (Created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-01-15 19:14 - 2019-01-15 19:14 - 000000000 ____D C:\FRST 2019-01-15 18:45 - 2019-01-15 18:45 - 000000000 ____D C:\ProgramData\Sophos 2019-01-15 18:44 - 2019-01-15 19:14 - 000000000 ____D C:\Users\Kurt\Desktop\PC Management 2019-01-15 18:44 - 2019-01-15 18:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos 2019-01-15 18:44 - 2019-01-15 18:44 - 000000000 ____D C:\Program Files (x86)\Sophos 2019-01-15 18:43 - 2019-01-15 18:43 - 000003156 _____ C:\WINDOWS\System32\Tasks\AdwCleaner_onReboot 2019-01-15 18:42 - 2019-01-15 18:43 - 000000000 ____D C:\AdwCleaner 2019-01-15 18:39 - 2018-12-17 19:01 - 000002303 _____ C:\Users\Kurt\Desktop\Google Chrome.lnk 2019-01-15 18:37 - 2019-01-15 18:38 - 000000000 ____D C:\Users\Kurt\Documents\misc 2019-01-15 18:35 - 2019-01-15 19:00 - 000253880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2019-01-15 18:35 - 2019-01-15 19:00 - 000110016 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2019-01-15 18:35 - 2019-01-15 19:00 - 000094144 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2019-01-15 18:35 - 2019-01-15 19:00 - 000046008 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2019-01-15 18:34 - 2019-01-15 18:41 - 000652724 _____ C:\WINDOWS\Minidump\011519-42890-01.dmp 2019-01-15 18:34 - 2019-01-15 18:34 - 1750953371 _____ C:\WINDOWS\MEMORY.DMP 2019-01-15 18:19 - 2019-01-15 18:19 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\442652BC.sys 2019-01-15 18:18 - 2019-01-15 18:20 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2019-01-15 17:52 - 2019-01-15 17:52 - 000193968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2019-01-15 17:48 - 2019-01-15 17:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2019-01-15 17:48 - 2017-11-29 09:11 - 000077432 _____ C:\WINDOWS\system32\Drivers\mbae64.sys 2019-01-15 17:46 - 2019-01-15 17:46 - 000000000 ____D C:\Users\Kurt\AppData\Local\mbamtray 2019-01-15 17:46 - 2019-01-15 17:46 - 000000000 ____D C:\Users\Kurt\AppData\Local\mbam 2019-01-15 17:44 - 2019-01-15 17:44 - 000000000 ____D C:\Program Files\Malwarebytes 2019-01-15 16:19 - 2019-01-15 16:23 - 095685215 _____ C:\Users\Kurt\Downloads\JoelRealTiming_v1.27.6.6_Setup_no_CUDA.zip 2019-01-14 12:10 - 2019-01-14 12:10 - 000000000 ____D C:\Program Files\vJoy 2019-01-14 12:09 - 2019-01-14 12:09 - 010545838 _____ (Shaul Eizikovich ) C:\Users\Kurt\Documents\vJoySetup.exe 2019-01-13 00:59 - 2019-01-13 00:59 - 000040087 _____ C:\Users\Kurt\Downloads\ShifterFW105.zip 2019-01-13 00:58 - 2019-01-13 00:58 - 000094208 _____ (Leo Bodnar Electronics) C:\Users\Kurt\Desktop\G25-G27-shifter-calibration.exe 2019-01-12 19:36 - 2019-01-12 19:36 - 000001315 _____ C:\Users\Kurt\Desktop\OculusDebugTool - Shortcut.lnk 2019-01-12 19:35 - 2019-01-12 19:35 - 000001036 _____ C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OculusDebugTool.lnk 2019-01-12 19:31 - 2019-01-12 19:33 - 000000000 ____D C:\Users\Kurt\Documents\homeless 2019-01-12 19:31 - 2019-01-12 19:31 - 000155858 _____ C:\Users\Kurt\Downloads\OculusHomeless (1).zip 2019-01-12 19:31 - 2018-06-29 09:43 - 000003877 _____ C:\Users\Kurt\Documents\README.txt 2019-01-12 19:31 - 2018-06-29 08:53 - 000307712 _____ C:\Users\Kurt\Documents\Home2-Win64-Shipping.exe 2019-01-12 19:31 - 2018-06-29 07:09 - 000000011 _____ C:\Users\Kurt\Documents\background_color.txt 2019-01-12 19:09 - 2019-01-12 19:09 - 000002013 _____ C:\Users\Public\Desktop\Oculus.lnk 2019-01-12 19:08 - 2019-01-12 19:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Oculus 2019-01-12 19:08 - 2019-01-12 19:08 - 001887232 _____ (OCULUS) C:\WINDOWS\system32\Drivers\OCULUS119B.sys 2019-01-12 19:08 - 2019-01-12 19:08 - 001721576 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01009.dll 2019-01-12 19:08 - 2019-01-12 19:08 - 000069176 _____ (Oculus VR, LLC) C:\WINDOWS\system32\Drivers\ocusbvid111.sys 2019-01-12 19:08 - 2019-01-12 19:08 - 000032856 _____ (Facebook Inc.) C:\WINDOWS\system32\Drivers\Oculus_ViGEmBus.sys 2019-01-12 18:58 - 2019-01-12 19:08 - 000000000 ____D C:\Program Files\Oculus 2019-01-12 18:37 - 2019-01-12 18:37 - 004209592 _____ (Oculus VR, LLC) C:\Users\Kurt\Documents\OculusSetup.exe 2019-01-12 17:59 - 2019-01-12 17:59 - 000155858 _____ C:\Users\Kurt\Downloads\OculusHomeless.zip 2019-01-12 17:56 - 2019-01-12 18:13 - 000000000 ____D C:\OculusSetup-DownloadCache-e09f238f-7dc4-44cc-9757-7d2ca2d5f2eb 2019-01-12 17:29 - 2018-10-14 08:39 - 000000000 ____D C:\Users\Kurt\Documents\oculus-diagnostics 2019-01-12 17:28 - 2019-01-12 17:28 - 033186311 _____ C:\Users\Kurt\Downloads\Oculus Small.zip 2019-01-12 17:28 - 2019-01-12 17:28 - 024520931 _____ C:\Users\Kurt\Downloads\oculus-diagnostics.zip 2019-01-12 11:30 - 2019-01-12 11:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Tools 2019-01-11 17:50 - 2019-01-11 17:50 - 004241060 _____ () C:\Users\Kurt\Documents\Jeff Gordon Spotter Pack for iRacing v0.4.exe 2019-01-11 17:30 - 2019-01-11 17:30 - 000293613 _____ C:\Users\Kurt\Downloads\NVIDIA_Inspector_1.9.7.8.zip 2019-01-11 17:30 - 2019-01-11 17:30 - 000000000 ____D C:\Users\Kurt\Downloads\NVIDIA_Inspector_1.9.7.8 2019-01-09 14:47 - 2019-01-01 07:50 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2019-01-09 14:47 - 2019-01-01 07:47 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowslivelogin.dll 2019-01-09 14:47 - 2019-01-01 07:46 - 012710912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2019-01-09 14:47 - 2019-01-01 07:45 - 000714752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll 2019-01-09 14:47 - 2019-01-01 07:45 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll 2019-01-09 14:47 - 2019-01-01 07:43 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll 2019-01-09 14:47 - 2019-01-01 07:20 - 011902976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2019-01-09 14:47 - 2019-01-01 07:20 - 000165888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowslivelogin.dll 2019-01-09 14:47 - 2019-01-01 07:18 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll 2019-01-09 14:47 - 2019-01-01 07:17 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll 2019-01-09 14:47 - 2019-01-01 01:14 - 001221432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2019-01-09 14:47 - 2019-01-01 01:14 - 001063224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2019-01-09 14:47 - 2019-01-01 01:14 - 001029944 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2019-01-09 14:47 - 2019-01-01 01:14 - 000566568 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2019-01-09 14:47 - 2019-01-01 01:14 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2019-01-09 14:47 - 2019-01-01 01:14 - 000076088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys 2019-01-09 14:47 - 2019-01-01 01:13 - 003292152 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2019-01-09 14:47 - 2019-01-01 01:13 - 001363536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2019-01-09 14:47 - 2019-01-01 01:13 - 000709728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2019-01-09 14:47 - 2019-01-01 01:13 - 000436024 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2019-01-09 14:47 - 2019-01-01 01:13 - 000170808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2019-01-09 14:47 - 2019-01-01 01:12 - 009084216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2019-01-09 14:47 - 2019-01-01 01:12 - 007520104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2019-01-09 14:47 - 2019-01-01 01:12 - 002765344 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2019-01-09 14:47 - 2019-01-01 01:12 - 002465792 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2019-01-09 14:47 - 2019-01-01 01:12 - 002421288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2019-01-09 14:47 - 2019-01-01 01:12 - 000713272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 2019-01-09 14:47 - 2019-01-01 01:12 - 000268304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2019-01-09 14:47 - 2019-01-01 01:12 - 000128824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys 2019-01-09 14:47 - 2019-01-01 01:12 - 000043536 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe 2019-01-09 14:47 - 2019-01-01 00:55 - 025856512 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2019-01-09 14:47 - 2019-01-01 00:50 - 022715392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2019-01-09 14:47 - 2019-01-01 00:50 - 004383744 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2019-01-09 14:47 - 2019-01-01 00:48 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe 2019-01-09 14:47 - 2019-01-01 00:48 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys 2019-01-09 14:47 - 2019-01-01 00:48 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Print.Workflow.Source.dll 2019-01-09 14:47 - 2019-01-01 00:47 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2019-01-09 14:47 - 2019-01-01 00:47 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe 2019-01-09 14:47 - 2019-01-01 00:46 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll 2019-01-09 14:47 - 2019-01-01 00:46 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll 2019-01-09 14:47 - 2019-01-01 00:46 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2019-01-09 14:47 - 2019-01-01 00:45 - 007573504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2019-01-09 14:47 - 2019-01-01 00:45 - 002368512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll 2019-01-09 14:47 - 2019-01-01 00:45 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll 2019-01-09 14:47 - 2019-01-01 00:44 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll 2019-01-09 14:47 - 2019-01-01 00:44 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2019-01-09 14:47 - 2019-01-01 00:44 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2019-01-09 14:47 - 2019-01-01 00:44 - 000662528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll 2019-01-09 14:47 - 2019-01-01 00:44 - 000456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.dll 2019-01-09 14:47 - 2019-01-01 00:43 - 001805312 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2019-01-09 14:47 - 2019-01-01 00:42 - 004939776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2019-01-09 14:47 - 2019-01-01 00:42 - 002247680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2019-01-09 14:47 - 2019-01-01 00:42 - 001371136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2019-01-09 14:47 - 2019-01-01 00:42 - 000717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2019-01-09 14:47 - 2019-01-01 00:41 - 001159680 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2019-01-09 14:47 - 2019-01-01 00:41 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2019-01-09 14:47 - 2019-01-01 00:41 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll 2019-01-09 14:47 - 2019-01-01 00:41 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll 2019-01-09 14:47 - 2019-01-01 00:37 - 006571584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2019-01-09 14:47 - 2019-01-01 00:37 - 002478664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2019-01-09 14:47 - 2019-01-01 00:37 - 002253696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2019-01-09 14:47 - 2019-01-01 00:37 - 001989040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll 2019-01-09 14:47 - 2019-01-01 00:37 - 000880048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2019-01-09 14:47 - 2019-01-01 00:37 - 000581808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVideoDSP.dll 2019-01-09 14:47 - 2019-01-01 00:37 - 000381240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2019-01-09 14:47 - 2019-01-01 00:29 - 022016512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2019-01-09 14:47 - 2019-01-01 00:22 - 019405312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2019-01-09 14:47 - 2019-01-01 00:17 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll 2019-01-09 14:47 - 2019-01-01 00:16 - 005775872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2019-01-09 14:47 - 2019-01-01 00:16 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll 2019-01-09 14:47 - 2019-01-01 00:16 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2019-01-09 14:47 - 2019-01-01 00:15 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2019-01-09 14:47 - 2019-01-01 00:15 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2019-01-09 14:47 - 2019-01-01 00:15 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll 2019-01-09 14:47 - 2019-01-01 00:15 - 000317440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll 2019-01-09 14:47 - 2019-01-01 00:14 - 004514816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2019-01-09 14:47 - 2019-01-01 00:14 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2019-01-09 14:47 - 2019-01-01 00:14 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.dll 2019-01-09 14:47 - 2019-01-01 00:13 - 001628160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2019-01-09 14:47 - 2019-01-01 00:13 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2019-01-09 14:47 - 2019-01-01 00:13 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2019-01-09 14:47 - 2019-01-01 00:12 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2019-01-09 14:47 - 2019-01-01 00:12 - 000795648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll 2019-01-09 14:47 - 2019-01-01 00:12 - 000778240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2019-01-09 14:47 - 2019-01-01 00:12 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll 2019-01-09 14:47 - 2018-12-31 23:23 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim 2019-01-09 14:47 - 2018-12-18 22:49 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll 2019-01-09 13:02 - 2019-01-09 13:02 - 000000000 ____D C:\Users\Kurt\AppData\Local\Dell Inc 2019-01-05 15:55 - 2019-01-05 15:55 - 000002377 _____ C:\Users\Kurt\Desktop\Soda Player.lnk 2019-01-04 19:46 - 2019-01-04 19:46 - 002799470 _____ ( ) C:\Users\Kurt\Documents\OTTSetup.exe 2019-01-01 18:42 - 2019-01-01 18:42 - 002123610 _____ C:\Users\Kurt\Documents\hau5_as3_visualizer_by_the1manwiththeplan-d34dw3w.swf 2019-01-01 18:20 - 2019-01-01 18:20 - 014896853 _____ C:\Users\Kurt\Documents\mindos__wip__by_minervaxcel-daxsyj6.rmskin 2019-01-01 18:13 - 2019-01-01 18:13 - 002025846 _____ C:\Users\Kurt\Documents\proteuschroma.rmskin 2019-01-01 18:10 - 2019-01-01 18:10 - 002025846 _____ C:\Users\Kurt\Documents\proteuschroma_v1_0_by_minervaxcel-dbbmjnm.rmskin 2019-01-01 18:09 - 2019-01-01 18:09 - 000358612 _____ C:\Users\Kurt\Documents\visbubble__round_visualizer_for_rainmeter_by_undefinist-d82wfbx.rmskin 2019-01-01 18:05 - 2019-01-01 18:05 - 001581521 _____ C:\Users\Kurt\Documents\thing_o_meter_hud_for_rainmeter_v1_0_by_birdalliance-d9z687m.rmskin 2019-01-01 17:16 - 2019-01-15 17:29 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\Plane9 2019-01-01 17:16 - 2019-01-01 17:16 - 000000000 ____D C:\Users\Kurt\AppData\Local\CrashRpt 2019-01-01 16:53 - 2019-01-01 16:53 - 003823871 _____ C:\Users\Kurt\Downloads\Monstercat-Visualizer-master (1).zip 2019-01-01 16:47 - 2019-01-01 16:47 - 000027235 _____ C:\Users\Kurt\Downloads\SpotifyPlugin-2.1.6-beta.2.zip 2019-01-01 16:45 - 2019-01-01 16:45 - 003823871 _____ C:\Users\Kurt\Downloads\Monstercat-Visualizer-master.zip 2019-01-01 16:44 - 2019-01-15 17:29 - 000000000 ____D C:\Program Files\Rainmeter 2019-01-01 16:22 - 2019-01-15 14:39 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\Spotify 2019-01-01 16:22 - 2019-01-15 13:11 - 000000000 ____D C:\Users\Kurt\AppData\Local\Spotify 2019-01-01 16:09 - 2019-01-01 16:35 - 000001847 _____ C:\Users\Kurt\Desktop\Spotify.lnk 2019-01-01 16:09 - 2019-01-01 16:35 - 000001833 _____ C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk 2019-01-01 14:04 - 2017-06-30 16:32 - 000001337 _____ C:\Users\Kurt\Desktop\iRacing.lnk 2018-12-21 14:46 - 2018-12-21 14:46 - 002942216 _____ C:\Users\Kurt\Documents\kurth.tga 2018-12-20 14:36 - 2018-12-14 01:29 - 001130760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll 2018-12-20 14:36 - 2018-12-14 01:25 - 001035256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2018-12-20 14:36 - 2018-12-14 01:21 - 001457240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2018-12-20 14:36 - 2018-12-14 01:21 - 001257672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2018-12-20 14:36 - 2018-12-14 01:21 - 001140480 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2018-12-20 14:36 - 2018-12-14 01:21 - 001098064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll 2018-12-20 14:36 - 2018-12-14 01:21 - 000982912 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2018-12-20 14:36 - 2018-12-14 01:10 - 001295360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2018-12-20 14:36 - 2018-12-14 01:07 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2018-12-20 14:36 - 2018-12-14 00:55 - 003396608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2018-12-20 14:36 - 2018-12-14 00:55 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2018-12-20 14:36 - 2018-12-14 00:54 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2018-12-20 14:36 - 2018-12-14 00:54 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll 2018-12-20 14:36 - 2018-12-14 00:52 - 002173440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2018-12-20 14:36 - 2018-12-14 00:52 - 001826816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll 2018-12-20 14:36 - 2018-12-14 00:51 - 001551360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2018-12-20 14:36 - 2018-12-14 00:50 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll ==================== One month (Modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-01-15 19:11 - 2018-04-11 17:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2019-01-15 19:05 - 2018-05-14 11:30 - 000840376 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2019-01-15 19:05 - 2018-04-11 17:36 - 000000000 ____D C:\WINDOWS\INF 2019-01-15 19:04 - 2018-05-23 09:29 - 000000000 ____D C:\ProgramData\NVIDIA 2019-01-15 19:00 - 2017-07-10 11:53 - 000000000 ____D C:\Users\Kurt\AppData\Local\Oculus 2019-01-15 18:59 - 2018-08-05 22:45 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2019-01-15 18:59 - 2018-05-14 11:40 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2019-01-15 18:58 - 2018-05-14 11:19 - 000000000 ____D C:\Users\Kurt 2019-01-15 18:58 - 2018-04-11 15:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI 2019-01-15 18:56 - 2016-08-15 11:32 - 000000000 ____D C:\Users\Kurt\AppData\Local\CrashDumps 2019-01-15 18:55 - 2016-08-12 15:53 - 000000000 ____D C:\Program Files (x86)\iRacing 2019-01-15 18:35 - 2018-05-14 11:13 - 000500304 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2019-01-15 18:34 - 2018-05-23 08:55 - 000000000 ____D C:\WINDOWS\Minidump 2019-01-15 18:34 - 2018-05-14 11:13 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2019-01-15 18:19 - 2017-03-28 16:23 - 000000000 ____D C:\ProgramData\Malwarebytes 2019-01-15 18:03 - 2016-08-24 15:56 - 000000000 ____D C:\Program Files (x86)\Steam 2019-01-15 17:44 - 2017-03-06 13:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2019-01-15 17:43 - 2017-03-06 13:48 - 000099192 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2019-01-15 17:43 - 2017-03-06 13:48 - 000000000 ____D C:\Program Files (x86)\Java 2019-01-15 17:30 - 2018-07-31 15:03 - 000000000 ____D C:\Program Files (x86)\Origin Games 2019-01-15 17:29 - 2018-07-16 12:33 - 000000000 ____D C:\Program Files\Common Files\Apple 2019-01-15 17:29 - 2016-12-14 10:00 - 000000000 ____D C:\ProgramData\Apple 2019-01-15 17:27 - 2018-04-11 17:38 - 000000000 ___HD C:\Program Files\WindowsApps 2019-01-15 17:27 - 2018-04-11 17:38 - 000000000 ____D C:\WINDOWS\AppReadiness 2019-01-15 17:25 - 2018-07-31 15:01 - 000000000 ____D C:\ProgramData\Origin 2019-01-15 17:22 - 2018-04-17 09:35 - 000000000 ____D C:\Program Files (x86)\Oculus Tray Tool 2019-01-15 16:51 - 2018-05-14 11:40 - 000004164 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E879354E-4F38-4C34-B7B4-A8A5A687C3C2} 2019-01-15 16:22 - 2017-07-10 13:53 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\OculusClient 2019-01-15 11:39 - 2017-02-15 18:52 - 000000000 ____D C:\Users\Kurt\AppData\Local\Discord 2019-01-15 11:39 - 2017-01-30 19:19 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\discord 2019-01-14 21:04 - 2017-08-11 11:08 - 000000038 _____ C:\Users\Kurt\AppData\Roaming\.OculusDebugToolGUI 2019-01-14 12:10 - 2018-07-27 13:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\vJoy 2019-01-13 19:37 - 2016-08-14 22:17 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\TS3Client 2019-01-12 19:37 - 2017-07-10 13:49 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\Oculus 2019-01-12 19:23 - 2018-11-07 20:11 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\Soda Player 2019-01-12 18:13 - 2018-05-23 09:29 - 000000000 ____D C:\Program Files (x86)\VulkanRT 2019-01-12 16:32 - 2016-08-12 17:21 - 000000000 ____D C:\Users\Kurt\Documents\iRacing 2019-01-12 14:36 - 2018-04-11 17:38 - 000000000 ____D C:\WINDOWS\TextInput 2019-01-12 14:36 - 2018-04-11 17:38 - 000000000 ____D C:\WINDOWS\bcastdvr 2019-01-12 14:11 - 2018-04-11 17:30 - 000000000 ____D C:\WINDOWS\CbsTemp 2019-01-12 11:30 - 2018-11-02 00:04 - 000002500 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business.lnk 2019-01-12 11:30 - 2018-11-02 00:04 - 000002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word.lnk 2019-01-12 11:30 - 2018-11-02 00:04 - 000002494 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint.lnk 2019-01-12 11:30 - 2018-11-02 00:04 - 000002458 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access.lnk 2019-01-12 11:30 - 2018-11-02 00:04 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel.lnk 2019-01-12 11:30 - 2018-11-02 00:04 - 000002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook.lnk 2019-01-12 11:30 - 2018-11-02 00:04 - 000002445 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher.lnk 2019-01-12 11:30 - 2018-11-02 00:04 - 000002437 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk 2019-01-12 11:29 - 2016-06-06 16:53 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2019-01-11 17:54 - 2017-07-13 12:53 - 000000000 ____D C:\Users\Kurt\AppData\Local\UnrealEngine 2019-01-10 12:12 - 2018-05-14 11:40 - 000003272 _____ C:\WINDOWS\System32\Tasks\D3DGearRawFrameCaptureTask 2019-01-10 12:01 - 2016-06-06 16:43 - 000000000 ____D C:\ProgramData\PCDr 2019-01-09 19:09 - 2018-06-12 07:44 - 000001016 _____ C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TRJ12_USB_ADAPTER_Calibration_Tool(V1.lnk 2019-01-09 14:57 - 2016-08-12 21:04 - 000000000 ____D C:\WINDOWS\system32\MRT 2019-01-09 14:54 - 2016-08-12 21:04 - 132790320 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2019-01-09 13:04 - 2016-06-06 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell 2019-01-09 13:02 - 2017-06-26 18:40 - 000000000 ____D C:\ProgramData\SupportAssist 2019-01-09 12:56 - 2016-08-12 16:15 - 000000000 ____D C:\Users\Kurt\AppData\Local\ElevatedDiagnostics 2019-01-08 20:32 - 2018-05-14 11:40 - 000004598 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier 2019-01-08 20:32 - 2018-04-11 17:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2019-01-08 20:32 - 2018-04-11 17:38 - 000000000 ____D C:\WINDOWS\system32\Macromed 2019-01-08 19:32 - 2018-05-14 11:40 - 000004586 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier 2019-01-07 20:47 - 2018-05-06 17:08 - 000000000 ____D C:\Users\Kurt\AppData\LocalLow\Mozilla 2019-01-07 03:12 - 2018-05-20 11:44 - 000004244 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate 2019-01-05 15:55 - 2018-11-07 20:11 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Soda Player 2019-01-05 15:55 - 2018-11-07 20:11 - 000000000 ____D C:\Users\Kurt\AppData\Local\sodaplayer 2019-01-05 15:55 - 2017-01-30 19:19 - 000000000 ____D C:\Users\Kurt\AppData\Local\SquirrelTemp 2019-01-05 12:47 - 2017-10-04 23:06 - 000000590 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics 2019-01-04 19:23 - 2018-06-03 19:43 - 000000888 _____ C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\irFFB.lnk 2019-01-02 13:41 - 2018-04-11 17:41 - 000835480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2019-01-02 13:41 - 2018-04-11 17:41 - 000179600 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2019-01-01 18:56 - 2018-01-02 15:10 - 000000000 ____D C:\Users\Kurt\AppData\Local\PlaceholderTileLogoFolder 2019-01-01 18:47 - 2017-11-02 17:54 - 000000000 ____D C:\Users\Kurt\AppData\Local\Packages 2019-01-01 13:58 - 2018-12-03 22:10 - 000000000 ____D C:\Users\Kurt\Documents\499 2019-01-01 13:58 - 2018-10-14 17:49 - 000000000 ____D C:\Users\Kurt\Documents\ffr 2018-12-21 12:00 - 2018-08-27 02:45 - 000000000 ____D C:\Program Files\Mozilla Firefox 2018-12-21 12:00 - 2018-08-27 02:45 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-12-20 05:33 - 2018-05-14 11:40 - 000003374 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1188590385-209233840-2562061582-1001 2018-12-20 05:33 - 2018-05-14 11:19 - 000002362 _____ C:\Users\Kurt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-12-20 05:33 - 2016-08-12 15:36 - 000000000 ___RD C:\Users\Kurt\OneDrive 2018-12-19 10:08 - 2018-05-14 11:40 - 000003418 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2018-12-19 10:08 - 2018-05-14 11:40 - 000003294 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2018-12-17 19:01 - 2016-08-13 15:50 - 000002303 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-12-16 21:51 - 2017-03-30 21:17 - 000000000 ____D C:\Users\Kurt\AppData\Roaming\TeamViewer 2018-12-16 10:39 - 2018-08-27 02:45 - 000001007 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2018-12-16 10:36 - 2018-12-13 10:55 - 000000000 ____D C:\Program Files\McAfee 2018-12-16 10:36 - 2016-06-06 16:46 - 000000000 ____D C:\ProgramData\McAfee ==================== Files in the root of some directories ======= 2018-07-24 21:56 - 2018-07-24 21:54 - 010776181 ____R () C:\Program Files\Windows Movie Maker 6.0.rar 2017-08-11 11:08 - 2019-01-14 21:04 - 000000038 _____ () C:\Users\Kurt\AppData\Roaming\.OculusDebugToolGUI 2018-02-11 15:00 - 2018-02-11 15:00 - 000143155 _____ () C:\Users\Kurt\AppData\Roaming\BodyProfileImage.png 2018-02-11 15:00 - 2018-02-11 15:00 - 000188358 _____ () C:\Users\Kurt\AppData\Roaming\ProfileImage.png 2017-07-21 14:28 - 2018-02-10 23:52 - 000033970 _____ () C:\Users\Kurt\AppData\Roaming\VoiceMeeterDefault.xml 2018-03-13 19:44 - 2018-03-13 19:44 - 000000044 _____ () C:\Users\Kurt\AppData\Roaming\WB.CFG 2017-12-28 13:24 - 2017-12-28 13:46 - 000015403 _____ () C:\Users\Kurt\AppData\Local\.starboard.aHR0cHM6Ly93d3cueW91dHViZS5jb20vdHY=.storage 2017-12-28 13:24 - 2017-12-28 13:24 - 000000000 _____ () C:\Users\Kurt\AppData\Local\.starboard.storage 2016-08-12 15:33 - 2019-01-15 19:00 - 004759891 _____ () C:\Users\Kurt\AppData\Local\BTServer.log 2017-02-24 20:37 - 2017-02-24 21:08 - 001307648 _____ () C:\Users\Kurt\AppData\Local\file__0.localstorage 2017-02-28 21:05 - 2017-04-09 19:13 - 000000552 _____ () C:\Users\Kurt\AppData\Local\TroubleshooterConfig.json Some files in TEMP: ==================== 2019-01-15 17:43 - 2019-01-15 17:43 - 001974624 _____ (Oracle Corporation) C:\Users\Kurt\AppData\Local\Temp\jre-8u201-windows-au.exe 2013-10-05 02:38 - 2013-10-05 02:38 - 000455328 _____ (Microsoft Corporation) C:\Users\Kurt\AppData\Local\Temp\msvcp120.dll 2013-10-05 02:38 - 2013-10-05 02:38 - 000970912 _____ (Microsoft Corporation) C:\Users\Kurt\AppData\Local\Temp\msvcr120.dll 2016-07-30 18:08 - 2016-07-30 18:08 - 003112960 _____ (Jason York) C:\Users\Kurt\AppData\Local\Temp\pc-decrapifier.exe 2019-01-01 16:08 - 2019-01-01 16:09 - 025972968 _____ (Spotify Ltd) C:\Users\Kurt\AppData\Local\Temp\SpotifyUninstall.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2018-05-14 11:13 ==================== End of FRST.txt ============================
  19. Here is FRST Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.01.2019 01 Ran by amy (administrator) on AMY-PC (14-01-2019 21:21:47) Running from C:\Users\amy\Desktop Loaded Profiles: amy (Available Profiles: amy & Administrator) Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) Language: English (United States) Internet Explorer Version 9 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (ATI Technologies Inc.) C:\Windows\System32\Ati2evxx.exe () C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Ulead Systems, Inc.) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe (Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\SeaPort.EXE (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239192 2018-06-14] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [90112 2006-11-10] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [248552 2010-05-14] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [vProt] => "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe" HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239192 2018-06-14] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239192 2018-06-14] (AVG Technologies CZ, s.r.o.) HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-20] (Microsoft Corporation) HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {1335b533-d022-11e5-9779-001e336b3e1b} - E:\Setup.exe HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {1e7219fc-e1ee-11e2-a919-001e336b3e1b} - F:\MotorolaDeviceManagerSetup.exe -a HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {203900ed-bfdd-11e5-a4ba-001e336b3e1b} - V:\Setup.exe HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {3d3fbd7d-d1de-11e5-97f4-001e336b3e1b} - E:\Setup.exe HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {9ab615ae-bfd4-11e5-9bc9-001e336b3e1b} - V:\Setup.exe HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {9b7c4c1d-bf8d-11e5-bf6c-001e336b3e1b} - V:\Setup.exe HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {a39841b6-b302-11e1-a154-001e336b3e1b} - F:\TL_Bootstrap.exe HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {a8b0f42b-bfb3-11e5-a772-001e336b3e1b} - V:\Setup.exe HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {e6bb18d9-d374-11e5-b467-001e336b3e1b} - E:\Setup.exe HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\MountPoints2: {fcc004cd-9336-11e1-a416-806e6f6e6963} - D:\wubi.exe HKLM\...\Drivers32-x32: [msacm.dvacm] => C:\Program Files (x86)\Common Files\Ulead Systems\vio\DVACM.acm [32768 2006-08-23] (Ulead Systems, Inc.) GroupPolicy: Restriction ? <==== ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.254.254 Tcpip\..\Interfaces\{B251A28E-4E33-49E5-8D18-E16203393569}: [DhcpNameServer] 192.168.254.254 Tcpip\..\Interfaces\{DDCA9E3E-F274-4979-995E-6C858ADF0520}: [DhcpNameServer] 192.168.254.254 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-12-18] (Adobe Systems Incorporated) BHO-x32: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG2012\avgssie.dll => No File BHO-x32: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG SafeGuard toolbar\19.7.0.632\AVG SafeGuard toolbar_toolbar.dll => No File BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll [2012-01-25] (Microsoft Corporation.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-05-01] (Sun Microsystems, Inc.) Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\19.7.0.632\AVG SafeGuard toolbar_toolbar.dll No File Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.355.0\BingExt.dll [2012-01-25] (Microsoft Corporation.) Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\amy\AppData\Roaming\Mozilla\Firefox\Profiles\kt23i23u.default [2019-01-14] FF Homepage: Mozilla\Firefox\Profiles\kt23i23u.default -> about:home FF Extension: (Firefox Hotfix) - C:\Users\amy\AppData\Roaming\Mozilla\Firefox\Profiles\kt23i23u.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-11-07] [Legacy] FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: (Microsoft .NET Framework Assistant) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-05-18] [Legacy] [not signed] FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\18.6.0.922 => not found FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_114.dll [2019-01-14] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_114.dll [2019-01-14] () FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\190.7.0\\npsitesafety.dll [No File] FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2012-05-01] (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-12-18] (Adobe Systems Inc.) ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335872 2019-01-14] (Adobe Systems Incorporated) [File not signed] R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5337696 2016-11-02] (AVG Technologies CZ, s.r.o.) R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428264 2018-06-14] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [727512 2016-11-02] (AVG Technologies CZ, s.r.o.) R2 TNaviSrv; C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [83312 2008-01-21] (TOSHIBA Corporation) R2 TODDSrv; C:\Windows\system32\TODDSrv.exe [135168 2007-11-21] (TOSHIBA Corporation) [File not signed] R2 UleadBurningHelper; C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) [File not signed] S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-20] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [312576 2016-10-17] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [267520 2016-10-19] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [254208 2016-09-26] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [299264 2016-07-27] (AVG Technologies CZ, s.r.o.) R0 avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.) S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (Created) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-01-14 21:21 - 2019-01-14 21:23 - 000012370 _____ C:\Users\amy\Desktop\FRST.txt 2019-01-14 21:21 - 2019-01-14 21:21 - 000000000 ____D C:\FRST 2019-01-14 21:13 - 2019-01-14 21:15 - 002427904 _____ (Farbar) C:\Users\amy\Desktop\FRST64.exe 2019-01-14 20:44 - 2019-01-14 20:48 - 000000000 ____D C:\AdwCleaner 2019-01-14 20:43 - 2019-01-14 20:43 - 007320272 _____ (Malwarebytes) C:\Users\amy\Downloads\AdwCleaner.exe 2019-01-14 20:39 - 2019-01-14 20:44 - 000001864 _____ C:\Users\amy\Desktop\Rkill.txt 2019-01-14 20:39 - 2019-01-14 20:39 - 000988112 _____ (Bleeping Computer, LLC) C:\Users\amy\Downloads\rkill64.exe 2019-01-14 20:38 - 2019-01-14 20:39 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\amy\Downloads\rkill.exe 2019-01-14 20:36 - 2019-01-14 21:10 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2019-01-14 20:23 - 2019-01-14 20:23 - 000004418 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier 2019-01-14 19:53 - 2019-01-14 21:06 - 000000000 ____D C:\Users\amy\AppData\Local\CrashDumps 2019-01-14 19:03 - 2019-01-14 20:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller 2019-01-14 19:03 - 2019-01-14 20:35 - 000000000 ____D C:\Program Files\RogueKiller 2019-01-14 18:38 - 2019-01-14 18:39 - 029181976 _____ (Adlice Software ) C:\Users\amy\Downloads\RogueKiller_setup_ref3.exe ==================== One month (Modified) ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2019-01-14 21:10 - 2012-05-01 16:09 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2019-01-14 21:00 - 2012-05-01 16:17 - 000000000 ____D C:\ProgramData\MFAData 2019-01-14 20:58 - 2006-11-02 10:42 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2019-01-14 20:58 - 2006-11-02 10:22 - 000004928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2019-01-14 20:58 - 2006-11-02 10:22 - 000004928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2019-01-14 20:56 - 2006-11-02 10:42 - 000032656 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2019-01-14 20:48 - 2016-01-23 18:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2019-01-14 20:25 - 2006-11-02 08:33 - 000000000 ____D C:\Windows\Cursors 2019-01-14 20:23 - 2012-05-13 00:58 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2019-01-14 20:23 - 2012-05-13 00:58 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2019-01-14 20:23 - 2012-05-13 00:58 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2019-01-14 20:22 - 2016-06-15 11:22 - 021301248 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe 2019-01-14 20:22 - 2012-06-26 18:23 - 000000000 ____D C:\Windows\system32\Macromed 2019-01-14 20:22 - 2012-05-01 16:22 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2019-01-14 19:57 - 2015-04-28 22:06 - 000192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2019-01-14 19:34 - 2006-11-02 10:21 - 000390168 _____ C:\Windows\system32\FNTCACHE.DAT 2019-01-14 19:01 - 2012-07-23 15:18 - 001842658 _____ C:\Windows\ntbtlog.txt ==================== Files in the root of some directories ======= 2013-06-16 10:38 - 2014-04-09 18:38 - 000003744 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml 2012-05-14 05:00 - 2012-05-22 18:35 - 000000680 _____ () C:\Users\amy\AppData\Local\d3d9caps.dat 2012-04-30 22:00 - 2016-02-24 19:44 - 000001460 _____ () C:\Users\amy\AppData\Local\d3d9caps64.dat 2012-05-01 16:12 - 2016-01-20 11:46 - 000006144 _____ () C:\Users\amy\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-05-01 16:49 - 2012-05-01 16:50 - 000375276 _____ () C:\Users\amy\AppData\Local\dd_vcredistMSI38BB.txt 2012-05-01 16:50 - 2012-05-01 16:50 - 000367478 _____ () C:\Users\amy\AppData\Local\dd_vcredistMSI394B.txt 2012-05-01 16:49 - 2012-05-01 16:50 - 000013352 _____ () C:\Users\amy\AppData\Local\dd_vcredistUI38BB.txt 2012-05-01 16:50 - 2012-05-01 16:50 - 000013128 _____ () C:\Users\amy\AppData\Local\dd_vcredistUI394B.txt 2016-02-11 12:43 - 2016-02-11 12:44 - 000011526 _____ () C:\Users\amy\AppData\Local\dd_vcredistUI79F8.txt 2016-02-11 12:44 - 2016-02-11 12:45 - 000011526 _____ () C:\Users\amy\AppData\Local\dd_vcredistUI7A9E.txt Some files in TEMP: ==================== 2013-09-24 07:49 - 2013-09-24 07:49 - 000000000 _____ () C:\Users\amy\AppData\Local\Temp\6cehsitp.dll 2016-01-20 14:51 - 2011-02-25 09:55 - 000161704 _____ (Autodesk, Inc.) C:\Users\amy\AppData\Local\Temp\AcDeltree.exe 2016-11-07 11:50 - 2016-05-18 12:03 - 000186640 _____ (AVG Technologies CZ, s.r.o.) C:\Users\amy\AppData\Local\Temp\avguirn_081407568511.exe 2016-05-15 18:51 - 2016-01-12 16:23 - 000179624 _____ (AVG Technologies CZ, s.r.o.) C:\Users\amy\AppData\Local\Temp\avguirn_081567571470.exe 2016-06-15 11:24 - 2016-04-22 09:01 - 000186640 _____ (AVG Technologies CZ, s.r.o.) C:\Users\amy\AppData\Local\Temp\avguirn_082026996632.exe 2013-06-30 20:37 - 2013-06-30 20:39 - 002991082 _____ (Motorola Mobility) C:\Users\amy\AppData\Local\Temp\MotoCast_Installer_2.0309.exe 2013-09-24 16:00 - 2013-09-24 16:00 - 004540440 _____ (AVG Secure Search) C:\Users\amy\AppData\Local\Temp\oi_{0BE369F9-5187-4222-9DBC-31B6F45BA067}.exe 2007-07-20 00:55 - 2007-07-20 00:55 - 000079720 _____ (Microsoft Corporation) C:\Users\amy\AppData\Local\Temp\Setup.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2019-01-14 21:04 ==================== End of FRST.txt ============================ Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14.01.2019 01 Ran by amy (14-01-2019 21:24:03) Running from C:\Users\amy\Desktop Windows Vista (TM) Home Premium Service Pack 2 (X64) (2012-05-01 02:46:49) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1046546136-2270861750-2775744828-500 - Administrator - Disabled) => C:\Users\Administrator amy (S-1-5-21-1046546136-2270861750-2775744828-1000 - Administrator - Enabled) => C:\Users\amy Guest (S-1-5-21-1046546136-2270861750-2775744828-501 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: AVG AntiVirus Free Edition (Enabled - Out of date) {4D41356F-32AD-7C42-C820-63775EE4F413} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: AVG AntiVirus Free Edition (Enabled - Out of date) {F620D48B-1497-73CC-F290-58052563BEAE} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov) Adobe Flash Player 32 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 32.0.0.114 - Adobe Systems Incorporated) Adobe Flash Player 9 ActiveX (HKLM-x32\...\{8E9DB7EF-5DD3-499E-BA2A-A1F3153A4DF8}) (Version: 9.0.115.0 - Adobe Systems, Inc.) Adobe Reader X (10.1.5) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.5 - Adobe Systems Incorporated) Atheros Driver Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 7.1 - Atheros) ATI Catalyst Install Manager (HKLM\...\{3C2673D2-8248-EDDC-B759-1D1D53C6709A}) (Version: 3.0.634.0 - ATI Technologies, Inc.) AutoCAD Electrical 2012 (HKLM\...\{5783F2D7-A007-0409-0102-0060B0CE6BBA}) (Version: 9.0.50.0 - Autodesk) Hidden AutoCAD Electrical 2012 (HKLM\...\AutoCAD Electrical 2012) (Version: 9.0.50.0 - Autodesk) AutoCAD Electrical 2012 Language Pack - English (HKLM\...\{5783F2D7-A007-0409-1102-0060B0CE6BBA}) (Version: 9.0.50.0 - Autodesk) Hidden AutoCAD Electrical 2016 Content Pack (HKLM\...\{5783F2D7-F007-0000-5102-0060B0CE6BBA}) (Version: 13.0.50.0 - Autodesk) Hidden Autodesk Content Service (HKLM-x32\...\{086F9A69-CD39-4893-A9FB-D3A0634CE3F7}) (Version: 2.0.90 - Autodesk) Autodesk Design Review 2012 (HKLM-x32\...\{A49BDCBE-590E-43A6-AB77-7C40E499B7C1}) (Version: 12.0.0.93 - Autodesk, Inc.) Hidden Autodesk Design Review 2012 (HKLM-x32\...\Autodesk Design Review 2012) (Version: 12.0.0.93 - Autodesk, Inc.) Autodesk Inventor View 2012 (HKLM\...\{76D6189D-1664-0400-0000-DFC2EE337EAC}) (Version: 16.0.15600.0000 - Autodesk) Hidden Autodesk Inventor View 2012 English (HKLM\...\Autodesk Inventor View 2012) (Version: 16.0.15600.0000 - Autodesk) Autodesk Inventor View 2012 English Language Pack (HKLM\...\{76D6189D-1664-0400-0001-DFC2EE337EAC}) (Version: 16.0.15600.0000 - Autodesk) Hidden Autodesk Material Library 2012 (HKLM-x32\...\{8F0837C2-EE09-4903-88F3-1976FE7FFF4E}) (Version: 2.5.0.8 - Autodesk) Autodesk Material Library Base Resolution Image Library 2012 (HKLM-x32\...\{65420DC9-306E-4371-905F-F4DC3B418E52}) (Version: 2.5.0.8 - Autodesk) Autodesk Vault 2012 (Client) (HKLM\...\{CF526A26-1664-0000-0000-02E95019B628}) (Version: 16.0.56.200 - Autodesk, Inc.) Hidden Autodesk Vault 2012 (Client) (HKLM-x32\...\Autodesk Vault 2012 (Client)) (Version: 16.0.56.200 - Autodesk, Inc.) Autodesk Vault 2012 (Client) English Language Pack (HKLM\...\{266597A9-1664-0000-0100-DCBF2B69166B}) (Version: 16.0.56.200 - Autodesk, Inc.) Hidden AVG (HKLM\...\{3D49031D-AEDF-4FC2-816F-CCE428CFA58A}) (Version: 16.131.7924 - AVG Technologies) Hidden AVG (HKLM\...\AvgZen) (Version: 1.113.2.50020 - AVG Technologies) AVG 2016 (HKLM\...\{C19A3151-EC41-4DF4-A2A9-14166CB8649E}) (Version: 16.0.4793 - AVG Technologies) Hidden AVG Protection (HKLM\...\AVG) (Version: 2016.131.7924 - AVG Technologies) AVG SafeGuard toolbar (HKLM-x32\...\AVG SafeGuard toolbar) (Version: 19.7.0.632 - AVG Technologies) AVG Zen (HKLM\...\{50B62078-D231-46A3-BA7C-23DCFA0E6101}) (Version: 1.113.1 - AVG Technologies) Hidden Bing Bar (HKLM-x32\...\{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation) Camera Assistant Software for Toshiba (HKLM-x32\...\{37C866E4-AA67-4725-9E95-A39968DD7960}) (Version: 1.7.175.0123 - Chicony Electronics Co.,Ltd.) Canon iP2700 series Printer Driver (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2700_series) (Version: - ) Catalyst Control Center - Branding (HKLM-x32\...\{D58A1E94-9EEA-4C6E-B9FB-D7C63DC6C941}) (Version: 1.00.0000 - ATI) ccc-core-static (HKLM-x32\...\{45ECDC05-71AC-6372-2A17-4139B6296F4F}) (Version: 2007.0815.2326.40058 - ATI) Hidden CPUID CPU-Z 1.74 (HKLM\...\CPUID CPU-Z_is1) (Version: - ) <==== ATTENTION CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - ) DVD MovieFactory for TOSHIBA (HKLM-x32\...\{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}) (Version: 5.51 - Ulead Systems, Inc.) DWG TrueView 2012 (HKLM\...\{5783F2D7-A028-0409-0100-0060B0CE6BBA}) (Version: 18.2.51.0 - Autodesk) Hidden DWG TrueView 2012 (HKLM\...\DWG TrueView 2012) (Version: 18.2.51.0 - Autodesk) FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production) FMW 1 (HKLM\...\{4CC5FB14-3F4D-4FA8-B921-00A9B40145C4}) (Version: 1.227.45 - AVG Technologies) Hidden HP Deskjet 3520 series Basic Device Software (HKLM\...\{A0A03B53-927D-4454-A456-CB0A72A4912F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Deskjet 3520 series Help (HKLM-x32\...\{C13E1F46-84FE-4D3B-8581-0F2F624C7EEC}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 3520 series Product Improvement Study (HKLM\...\{14ABDFC2-491B-4AF0-8134-CC5596D0EF57}) (Version: 28.0.1315.0 - Hewlett-Packard Co.) HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Update (HKLM-x32\...\{6F1C00D2-25C2-4CBA-8126-AE9A6E2E9CD5}) (Version: 5.003.003.001 - Hewlett-Packard) Java(TM) 6 Update 22 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216022FF}) (Version: 6.0.220 - Oracle) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Chart Controls for Microsoft .NET Framework 3.5 (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.0.0 - Microsoft Corporation) Microsoft DirectX SDK (August 2007) (HKLM-x32\...\{F0A4913F-46A5-48F2-BC73-EE41A6C81EB3}) (Version: 9.20.1057 - Microsoft® Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 43.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla) OpenOffice.org 3.3 (HKLM-x32\...\{3E171899-0175-47CC-84C4-562ACDD4C021}) (Version: 3.3.9567 - OpenOffice.org) Realtek 8169 8168 8101E 8102E Ethernet Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0000 - Realtek) REALTEK RTL8187B Wireless LAN Driver (HKLM-x32\...\{895722FE-25FE-4854-95AC-B0C42F9DBEDA}) (Version: Package:1.00.0026 Driver:6.1116.1226.2007 - REALTEK Semiconductor Corp.) RogueKiller version 13.0.22.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 13.0.22.0 - Adlice Software) SeaTools for Windows (HKLM-x32\...\{98613C99-1399-416C-A07C-1EE1C585D872}) (Version: 1.2.0.5 - Seagate Technology) Skins (HKLM-x32\...\{06F2B3DC-74F4-300D-D41A-B21B46101CA2}) (Version: 2007.0815.2326.40058 - ATI) Hidden Skype™ 5.10 (HKLM-x32\...\{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}) (Version: 5.10.116 - Skype Technologies S.A.) TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.0.1.3 for x64 - TOSHIBA Corporation) TOSHIBA DVD PLAYER (HKLM-x32\...\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}) (Version: 1.20.10 - TOSHIBA Corporation) Visual Studio 2008 x64 Redistributables (HKLM-x32\...\{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}) (Version: 10.0.0.2 - AVG Technologies) Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies) Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.) Web Companion (HKLM-x32\...\{54d0d201-5c04-4e7d-9aa5-16ee478fecc2}) (Version: 2.1.1265.2535 - Lavasoft) WinCDEmu (HKLM-x32\...\WinCDEmu) (Version: 4.1 - Sysprogs) Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version: - ) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2012\dwgviewrficn.dll (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\Autodesk\Acade 2012\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000_Classes\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}\localserver32 -> C:\Users\amy\AppData\Local\Chromium\Application\46.0.2480.0\delegate_execute.exe (The Chromium Authors) <==== ATTENTION CustomCLSID: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000_Classes\CLSID\{B77E471C-FBF3-4CB5-880F-D7528AD4B349}\localserver32 -> C:\Program Files\Autodesk\Acade 2012\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000_Classes\CLSID\{C92FB640-AD4D-498A-9979-A51A2540C977}\localserver32 -> C:\Program Files\Autodesk\Acade 2012\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\Autodesk\Acade 2012\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\Acade 2012\acadficn.dll (Autodesk, Inc.) ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2011-02-04] (Autodesk, Inc.) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2011-02-04] (Autodesk) ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2011-01-10] (Autodesk, Inc.) ContextMenuHandlers1-x32: [AVG Shell Extension] -> {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} => C:\Program Files (x86)\AVG\Av\avgsea.dll [2016-11-02] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers1-x32: [WinCDEmu] -> {D0E37FD2-F675-426F-B09A-2CF37BA46FD5} => C:\Program Files (x86)\WinCDEmu\x64\WinCDEmuContextMenu.dll [2015-09-28] (Sysprogs OU) ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll -> No File ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File ContextMenuHandlers2: [WinCDEmu] -> {A9901FCD-B4DF-43A1-BD5D-6C9F88679497} => C:\Program Files (x86)\WinCDEmu\x64\WinCDEmuContextMenu.dll [2015-09-28] (Sysprogs OU) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) ContextMenuHandlers4: [Convert] -> {9f95ca1a-e80e-4c0f-acd1-4c9b7900b982} => C:\Program Files (x86)\Microsoft DirectX SDK (August 2007)\Utilities\Bin\x64\TxView.DLL [2007-07-20] (Microsoft Corporation) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2007-03-02] () ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) ContextMenuHandlers6: [AVG Shell Extension] -> {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} => C:\Program Files (x86)\AVG\Av\avgsea.dll [2016-11-02] (AVG Technologies CZ, s.r.o.) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes) ContextMenuHandlers6: [WinCDEmu] -> {A9901FCD-B4DF-43A1-BD5D-6C9F88679497} => C:\Program Files (x86)\WinCDEmu\x64\WinCDEmuContextMenu.dll [2015-09-28] (Sysprogs OU) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll -> No File ContextMenuHandlers6: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => -> No File ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {178F5D8A-650C-4C70-B2DD-2C27645222F9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2019-01-14] (Adobe Systems Incorporated) Task: {1CCD050E-1A21-4A79-97BE-588FC30978C7} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_114_Plugin.exe [2019-01-14] (Adobe Systems Incorporated) Task: {3C35BAEC-9D06-4E54-B504-27800D40EE98} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe Task: {3F485640-2C8B-41BC-A4F4-5C2B17FE399A} - System32\Tasks\HPCustParticipation HP Deskjet 3520 series => C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.) Task: {5EDE2FDF-E3BC-4F4E-B2EE-A85E48C9D0DB} - \UpdateTask -> No File <==== ATTENTION Task: {A87C1079-3F3A-4E74-8C5D-2BE423C9E6FB} - System32\Tasks\ROC_REG_JAN_DELETE => C:\ProgramData\AVG January 2013 Campaign\ROC.exe [2013-01-17] () (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\ROC_REG_JAN_DELETE.job => C:\ProgramData\AVG January 2013 Campaign\ROC.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) WMI:subscription\CommandLineEventConsumer->BVTConsumer: ==================== Loaded Modules (Whitelisted) ============== 2007-07-28 00:26 - 2007-07-28 00:26 - 000116736 _____ () C:\Windows\system32\atitmm64.dll 2011-02-02 14:08 - 2011-02-02 14:08 - 000018656 _____ () C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe 2007-12-12 14:46 - 2007-12-12 14:46 - 000016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2017-01-04 19:47 - 2017-01-04 19:46 - 048920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) HKLM\...\cmdfile\DefaultIcon: %SystemRoot%\System32\shell32.dll,-153 <==== ATTENTION HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1" ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\.DEFAULT\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\...\localhost -> localhost ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 07:34 - 2016-01-23 18:32 - 000000761 _____ C:\Windows\system32\drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\Microsoft DirectX SDK (August 2007)\Utilities\Bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\PROGRA~2\COMMON~1\ULEADS~1\MPEG HKU\S-1-5-21-1046546136-2270861750-2775744828-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\amy\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg DNS Servers: 192.168.254.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == If an entry is included in the fixlist, it will be removed. MSCONFIG\startupreg: ADSKAppManager => "C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe" -showminimized -checkautorun MSCONFIG\startupreg: Camera Assistant Software => "C:\Program Files (x86)\Camera Assistant Software for Toshiba\traybar.exe" /start MSCONFIG\startupreg: GoogleChromeAutoLaunch_4AAE28A3955B0D25EEDCABFA27234336 => "C:\Users\amy\AppData\Local\Chromium\Application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session MSCONFIG\startupreg: HP Deskjet 3520 series (NET) => "C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN3911C1ZK05SY:NW" -scfn "HP Deskjet 3520 series (NET)" -AutoStart 1 MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Windows Defender => %ProgramFiles%\Windows Defender\MSASCui.exe -hide ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [WinCollab-Out-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe No File FirewallRules: [WinCollab-In-UDP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe No File FirewallRules: [WinCollab-Out-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe No File FirewallRules: [WinCollab-In-TCP] => (Allow) %ProgramFiles%\Windows Collaboration\WinCollab.exe No File FirewallRules: [WinCollab-DFSR-Out-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe (Microsoft Corporation) FirewallRules: [WinCollab-DFSR-In-TCP] => (Allow) %SystemRoot%\system32\dfsr.exe (Microsoft Corporation) FirewallRules: [{95DE448D-0499-48BF-82E3-AB9C3908A6EE}] => (Allow) LPort=80 FirewallRules: [{E531DF07-3DB1-40A5-BAFD-8F99ED51FFE8}] => (Allow) LPort=80 FirewallRules: [{DA2DE2C4-1178-4FB7-AABE-D9F814141CC5}] => (Allow) LPort=80 FirewallRules: [{9772E910-82BC-4B85-B93A-19D5EFA4E3D4}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe No File FirewallRules: [{A021E481-0686-4FE8-85E6-599373B08E87}] => (Allow) C:\Program Files (x86)\AVG\AVG2012\avgmfapx.exe No File FirewallRules: [{1082745A-5A28-4662-A070-0AA82A4E0087}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.) FirewallRules: [{147E7973-D1B1-401B-B920-171ECB2D3279}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe No File FirewallRules: [{AE4DCCB9-C947-4BBD-9173-1EABCB13DB7F}] => (Allow) C:\Program Files (x86)\AVG\AVG2014\avgmfapx.exe No File FirewallRules: [{821349FC-3AE9-4135-8282-9182E56E1FEB}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\DeviceSetup.exe (Hewlett-Packard Co.) FirewallRules: [{20BF8295-7228-4723-A427-E3DA67A7F2F8}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe (Hewlett-Packard Co.) FirewallRules: [{5D66331F-3ECC-4D96-A8F6-78DDA0873E02}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.) FirewallRules: [{4C71FFB9-E2B6-4916-A14F-6C8DFCD72B14}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) FirewallRules: [{2D7B7B91-619B-4D94-852D-C4CD57C89554}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) FirewallRules: [{6DC9E969-46E3-4FE1-AB18-164013A179F2}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe (AVG Technologies CZ, s.r.o.) FirewallRules: [{FA7A3BEA-871B-4607-B1B3-88492AAA0B95}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe (AVG Technologies CZ, s.r.o.) FirewallRules: [{8A70E8D6-B40A-4CDC-8001-F74F3273CAAC}] => (Allow) C:\Users\amy\AppData\Local\Chromium\Application\chrome.exe (The Chromium Authors) FirewallRules: [{6215E282-48EA-4D61-9F86-B5C94A7BDCAD}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe (AVG Technologies CZ, s.r.o.) FirewallRules: [{28EBD1AD-D3AB-4959-88CF-9A3A023CFF19}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe (AVG Technologies CZ, s.r.o.) FirewallRules: [{FF0DD3BA-1088-40AA-96E4-83DD0973AA10}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe (AVG Technologies CZ, s.r.o.) FirewallRules: [{1D36F008-DA70-45AF-BC44-E6C1B46184C5}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe (AVG Technologies CZ, s.r.o.) ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/14/2019 09:06:35 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application RogueKiller64.exe, version 13.0.22.0, time stamp 0x5c3cba1d, faulting module KERNEL32.dll!K32GetModuleInformation, version 6.0.6002.19514, time stamp 0x561e783a, exception code 0xc0000139, fault offset 0x00000000000b7398, process id 0x780, application start time 0x01d4ac76ecfbda9d. Error: (01/14/2019 08:36:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application RogueKiller64.exe, version 13.0.22.0, time stamp 0x5c3cba1d, faulting module KERNEL32.dll!K32GetModuleInformation, version 6.0.6002.19514, time stamp 0x561e783a, exception code 0xc0000139, fault offset 0x00000000000b7398, process id 0x1570, application start time 0x01d4ac72aea8c125. Error: (01/14/2019 08:35:16 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application RogueKiller64.exe, version 13.0.22.0, time stamp 0x5c3cba1d, faulting module KERNEL32.dll!K32GetModuleInformation, version 6.0.6002.19514, time stamp 0x561e783a, exception code 0xc0000139, fault offset 0x00000000000b7398, process id 0xa74, application start time 0x01d4ac728dccb4c5. Error: (01/14/2019 08:27:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application loggingserver.exe, version 17.2.0.0, time stamp 0x51d41c91, faulting module log4cplusU.dll, version 6.0.6002.19514, time stamp 0x561e7b31, exception code 0xc0000135, fault offset 0x0006f40f, process id 0x5d0, application start time 0x01d4ac7187788c35. Error: (01/14/2019 07:52:12 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application RogueKiller64.exe, version 13.0.22.0, time stamp 0x5c3cba1d, faulting module KERNEL32.dll!K32GetModuleInformation, version 6.0.6002.19514, time stamp 0x561e783a, exception code 0xc0000139, fault offset 0x00000000000b7398, process id 0x650, application start time 0x01d4ac6b8ab9a9db. Error: (01/14/2019 07:34:05 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application loggingserver.exe, version 17.2.0.0, time stamp 0x51d41c91, faulting module log4cplusU.dll, version 6.0.6002.19514, time stamp 0x561e7b31, exception code 0xc0000135, fault offset 0x0006f40f, process id 0x11dc, application start time 0x01d4ac69ff4ce73f. Error: (01/14/2019 07:00:50 PM) (Source: EventSystem) (EventID: 4609) (User: ) Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007043c from line 45 of d:\longhorn\com\complus\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error. Error: (01/13/2019 11:22:56 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application loggingserver.exe, version 17.2.0.0, time stamp 0x51d41c91, faulting module log4cplusU.dll, version 6.0.6002.19514, time stamp 0x561e7b31, exception code 0xc0000135, fault offset 0x0006f40f, process id 0x11ac, application start time 0x01d4ab5c3b87ed85. System errors: ============= Error: (01/14/2019 08:59:06 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied. Error: (01/14/2019 08:59:06 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied. Error: (01/14/2019 08:58:01 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 412) (User: NT AUTHORITY) Description: Event-ID 412 Error: (01/14/2019 08:56:35 PM) (Source: Service Control Manager) (EventID: 7006) (User: ) Description: The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied. Error: (01/14/2019 08:48:46 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Software Licensing service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. Error: (01/14/2019 08:48:45 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The BBUpdate service terminated unexpectedly. It has done this 1 time(s). Error: (01/14/2019 08:48:45 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Autodesk Content Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Error: (01/14/2019 08:48:45 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s). CodeIntegrity: =================================== Date: 2019-01-14 21:23:06.773 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avguniva.sys because the set of per-page image hashes could not be found on the system. Date: 2019-01-14 21:23:06.145 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avguniva.sys because the set of per-page image hashes could not be found on the system. Date: 2019-01-14 21:23:05.517 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avguniva.sys because the set of per-page image hashes could not be found on the system. Date: 2019-01-14 21:23:04.843 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avguniva.sys because the set of per-page image hashes could not be found on the system. Date: 2019-01-14 21:23:04.134 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avguniva.sys because the set of per-page image hashes could not be found on the system. Date: 2019-01-14 21:23:03.474 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avguniva.sys because the set of per-page image hashes could not be found on the system. Date: 2019-01-14 21:23:02.782 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avguniva.sys because the set of per-page image hashes could not be found on the system. Date: 2019-01-14 21:23:01.880 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\avguniva.sys because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: AMD Turion(tm) 64 X2 Mobile Technology TL-60 Percentage of memory in use: 64% Total physical RAM: 3964.7 MB Available physical RAM: 1420.15 MB Total Virtual: 8151.93 MB Available Virtual: 5441.94 MB ==================== Drives ================================ Drive 😄 () (Fixed) (Total:231.42 GB) (Free:157.54 GB) NTFS ==>[drive with boot components (obtained from BCD)] \\?\Volume{fcc004c9-9336-11e1-a416-806e6f6e6963}\ (TOSHIBA SYSTEM VOLUME) (Fixed) (Total:1.46 GB) (Free:1.3 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: 30D25FA8) Partition 1: (Not Active) - (Size=1.5 GB) - (Type=27) Partition 2: (Active) - (Size=231.4 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================
  20. Broni I did this in the order that i could it was running so bad . I have a Malwarebytes log , got RogueKiller downloaded but would not run the error was " The procedure entry point K32GetModuleInformation could not be located in the dynamic link library KERNEL32.dll " Thinking something was wrong I did the "sfc /scannow" , said fixed most but not all , I copied that log . Then "RKill" Got "AdwCleaner " ran it , if froze at the end but did seem to do its job , does seem better at times but still acts up , even took notepad almost 5 minutes to show . It does not freeze up , just doesn't respond for quite some time !!! I will post in the order I ran , sorry didn't have "FRST" till the end . Rkill 2.9.1 by Lawrence Abrams (Grinler) http://www.bleepingcomputer.com/ Copyright 2008-2019 BleepingComputer.com More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html Program started at: 01/14/2019 08:39:34 PM in x64 mode. Windows Version: Windows Vista (TM) Home Premium Service Pack 2 Checking for Windows services to stop: * No malware services found to stop. Checking for processes to terminate: * C:\Windows\system32\TODDSrv.exe (PID: 4000) [WD-HEUR] 1 proccess terminated! Checking Registry for malware related settings: * No issues found in the Registry. Resetting .EXE, .COM, & .BAT associations in the Windows Registry. Performing miscellaneous checks: * Windows Defender Disabled [HKLM\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware" = dword:00000001 Searching for Missing Digital Signatures: Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 1/14/2019 Scan Time: 7:57:43 PM Logfile: mbamlog.txt Administrator: Yes Version: 2.2.1.1043 Malware Database: v2019.01.15.01 Rootkit Database: v2019.01.15.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows Vista Service Pack 2 CPU: x64 File System: NTFS User: amy Scan Type: Threat Scan Result: Completed Objects Scanned: 212323 Time Elapsed: 25 min, 38 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Warn PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 0 (No malicious items detected) Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 0 (No malicious items detected) Files: 1 PUP.Optional.ByteFence, C:\Users\amy\AppData\Local\Temp\tmpSec7109913\bytefence-installer_2.1.0.3.exe, Quarantined, [2b824eb29e29280e23ee9415b2518779], Physical Sectors: 0 (No malicious items detected) (end) # ------------------------------- # Malwarebytes AdwCleaner 7.2.6.0 # ------------------------------- # Build: 12-18-2018 # Database: 2019-01-10.1 (Cloud) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Clean # ------------------------------- # Start: 01-14-2019 # Duration: 00:00:08 # OS: Windows Vista (TM) Home Premium # Cleaned: 96 # Failed: 6 ***** [ Services ] ***** Deleted vToolbarUpdater190.7.0 Deleted vToolbarUpdater17.3.0 Deleted SearchProtectionService Deleted LavasoftTcpService ***** [ Folders ] ***** Deleted C:\ProgramData\AVG Security Toolbar Deleted C:\ProgramData\AVG Secure Search Deleted C:\Program Files\Common Files\AVG Secure Search Deleted C:\Program Files (x86)\Common Files\AVG Secure Search Deleted C:\ProgramData\AVG SafeGuard toolbar Deleted C:\Program Files (x86)\AVG SafeGuard toolbar Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar Deleted C:\Users\Administrator\AppData\Local\AVG SafeGuard toolbar Deleted C:\Users\amy\AppData\Local\AVG SafeGuard toolbar Deleted C:\Users\Administrator\AppData\LocalLow\AVG SafeGuard toolbar Deleted C:\Users\amy\AppData\LocalLow\AVG SafeGuard toolbar Deleted C:\Windows\SysWOW64\config\systemprofile\AppData\Local\LavasoftTcpService Deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion ***** [ Files ] ***** Deleted C:\Users\amy\AppData\Roaming\Mozilla\Firefox\Profiles\kt23i23u.default\searchplugins\bing-lavasoft.xml Deleted C:\Users\amy\AppData\Roaming\Mozilla\Firefox\Profiles\kt23i23u.default\searchplugins\avg-secure-search.xml Deleted C:\Windows\System32\LavasoftTcpService64.dll Deleted C:\Windows\System32\LavasoftTcpServiceOff.ini Deleted C:\Windows\SysWOW64\LavasoftTcpServiceOff.ini Deleted C:\Windows\SysWOW64\lavasofttcpservice.dll ***** [ DLL ] ***** No malicious DLLs cleaned. ***** [ WMI ] ***** No malicious WMI cleaned. ***** [ Shortcuts ] ***** No malicious shortcuts cleaned. ***** [ Tasks ] ***** Deleted C:\Windows\Tasks\updateTask.job Deleted C:\Windows\System32\Tasks\updateTask ***** [ Registry ] ***** Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ByteFence Deleted HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Reason\ReasonByteFence Deleted HKLM\Software\Wow6432Node\Microsoft\Shared Tools\MSConfig\startupreg\NowUSeeIt Player Deleted HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\NowUSeeIt Player Deleted HKLM\Software\Wow6432Node\Microsoft\Shared Tools\MSConfig\startupreg\Web Companion Deleted HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\Web Companion Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{83245CDF-A15E-49E9-BE6D-AC32E96FCE78} Deleted HKCU\Software\yahooprovidedsearch Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{fd13f4a2-b0d8-4cad-9ccf-d4128eaf25ff}_is1 Deleted HKLM\Software\Wow6432Node\Classes\protocols\handler\viprotocol Deleted HKLM\SOFTWARE\Classes\protocols\handler\viprotocol Deleted HKLM\Software\Wow6432Node\Classes\AppID\ViProtocol.DLL Deleted HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Deleted HKLM\Software\Wow6432Node\Classes\AppID\ScriptHelper.EXE Deleted HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057} Deleted HKLM\Software\Classes\TypeLib\{ED62BC6E-64F1-46BE-866F-4C8DC0DF7057} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{FCAA532B-E807-4027-940C-BA16B9D50105} Deleted HKLM\Software\Classes\CLSID\{FCAA532B-E807-4027-940C-BA16B9D50105} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{CB31FF8F-BF80-4D2B-ADBE-12C6F5347890} Deleted HKLM\Software\Classes\CLSID\{CB31FF8F-BF80-4D2B-ADBE-12C6F5347890} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{9A754403-27B1-4ED7-96D7-588F07888EBF} Deleted HKLM\Software\Classes\CLSID\{9A754403-27B1-4ED7-96D7-588F07888EBF} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{8F010D54-C023-457F-AF03-497EACB6D519} Deleted HKLM\Software\Classes\CLSID\{8F010D54-C023-457F-AF03-497EACB6D519} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{472EF1D2-4AAE-470D-AE85-6AF8177916FD} Deleted HKLM\Software\Classes\CLSID\{472EF1D2-4AAE-470D-AE85-6AF8177916FD} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{3A5A5381-DAAF-4C0D-B032-2C66B3EE4A8D} Deleted HKLM\Software\Classes\CLSID\{3A5A5381-DAAF-4C0D-B032-2C66B3EE4A8D} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{26C7AFDB-3690-449E-B979-B0AF5CC56DD4} Deleted HKLM\Software\Classes\CLSID\{26C7AFDB-3690-449E-B979-B0AF5CC56DD4} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{0015CAC9-FC30-4CD0-BFAA-7412CC2C4DD9} Deleted HKLM\Software\Classes\CLSID\{0015CAC9-FC30-4CD0-BFAA-7412CC2C4DD9} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615} Deleted HKLM\Software\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Deleted HKLM\Software\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Deleted HKLM\Software\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Deleted HKLM\Software\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Deleted HKLM\Software\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Deleted HKLM\Software\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Deleted HKLM\Software\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Deleted HKLM\Software\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Deleted HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Deleted HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Deleted HKLM\Software\Wow6432Node\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Deleted HKLM\Software\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} Deleted HKLM\Software\Wow6432Node\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Deleted HKLM\Software\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Deleted HKLM\Software\Wow6432Node\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE} Deleted HKLM\Software\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE} Deleted HKLM\Software\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Deleted HKLM\Software\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Not Deleted HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\updateTask Not Deleted HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5EDE2FDF-E3BC-4F4E-B2EE-A85E48C9D0DB} Not Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5EDE2FDF-E3BC-4F4E-B2EE-A85E48C9D0DB} Not Deleted HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5EDE2FDF-E3BC-4F4E-B2EE-A85E48C9D0DB} Not Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5EDE2FDF-E3BC-4F4E-B2EE-A85E48C9D0DB} Not Deleted HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\updateTask Deleted HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Deleted HKCU\Software\Microsoft\Internet Explorer\Main|Start Page Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C0AFC06A-6C9E-420F-AABF-B1AC7EE1F589} Deleted HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com Deleted HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com Deleted HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com Deleted HKLM\Software\Wow6432Node\Classes\AppID\LavasoftTcpService.exe Deleted HKLM\SOFTWARE\Classes\AppID\LavasoftTcpService.exe Deleted HKLM\Software\Wow6432Node\Classes\AppID\{2CE0F1DC-C504-4B7B-A385-D94A2531DFFB} Deleted HKLM\Software\Classes\AppID\{2CE0F1DC-C504-4B7B-A385-D94A2531DFFB} ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries cleaned. ***** [ Chromium URLs ] ***** No malicious Chromium URLs cleaned. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries cleaned. ***** [ Firefox URLs ] ***** No malicious Firefox URLs cleaned. ************************* [+] Delete Tracing Keys [+] Reset Winsock ************************* AdwCleaner[S00].txt - [11827 octets] - [14/01/2019 20:45:20] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
  21. Broni

    Welcome KQuist95

    Hello KQuist95, Welcome to Smartest Computing. Please feel free to browse around and get to know the others. If you have any questions please don't hesitate to ask. KQuist95 joined on the 01/15/2019. View Member
  22. Yesterday
  23. frazzm737

    Daily picture

    That would make a lovely handbag if it would hold still...
  24. frazzm737

    Carol Channing

  25. frazzm737

    Shutdown

  26. frazzm737

    The Wall

  27. frazzm737

    Breaking News

  1. Load more activity
×