Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проверка за някакви нередности

Featured Replies

Имам проблеми със SSD-то, възможно ли е да направим една проверчица, за да знам дали има нещо нередно от към софтуерна гледна точка?

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-06-2017
Ran by Kris (administrator) on KRIS-PC (12-06-2017 18:28:59)
Running from C:\Users\Kris\Desktop
Loaded Profiles: Kris (Available Profiles: Kris)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\igfxCUIService.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe
(Intel(R) Corporation) C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(eVenture Limited) C:\Program Files (x86)\hide.me VPN\hidemesvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(Highresolution Enterprises) C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.10\Lightshot.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera.exe
(Opera Software) C:\Program Files\Opera\45.0.2552.888\opera.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
(v5^dev) C:\Users\Kris\Desktop\DOB LOVE\DOB_Gui.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1705.1301.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Maxthon International ltd.) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-28] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8899592 2017-04-29] (Realtek Semiconductor)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2017-04-30] (Pixart Imaging Inc)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-05-05] (Adobe Systems Incorporated)
HKLM\...\Run: [XMouseButtonControl] => C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe [1487896 2017-02-08] (Highresolution Enterprises)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23819304 2017-03-21] (Google)
HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27716568 2017-05-04] (Skype Technologies S.A.)
HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\...\Run: [CyberGhost] => "C:\Program Files\CyberGhost 6\CyberGhost.exe" /autostart /min
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 127.0.0.1 activation.cloud.techsmith.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0924ac9e-ff20-4961-81a5-36bd36df3c24}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-15] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-15] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: ei5xjl3l.default
FF ProfilePath: C:\Users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\ei5xjl3l.default [2017-06-11]
FF Extension: (Follow-on Search Telemetry) - C:\Users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\ei5xjl3l.default\features\{51347a27-d55a-4c17-8eab-ea099dfa077b}\[email protected] [2017-06-11]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-28] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-15] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-15] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-28] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll [2012-04-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-05-01] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-05-01] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-30] (Google Inc.)

Chrome: 
=======
CHR Profile: C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default [2017-06-09]
CHR Extension: (Google Slides) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-05-02]
CHR Extension: (Google Docs) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-02]
CHR Extension: (Google Drive) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-02]
CHR Extension: (YouTube) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-02]
CHR Extension: (Google Sheets) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-05-02]
CHR Extension: (Google Docs Offline) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-02]
CHR Extension: (Gmail) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-02]
CHR Extension: (Chrome Media Router) - C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-19]
CHR HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

Opera: 
=======
StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2015-05-09] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-04-25] () [File not signed]
S3 cphs; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\IntelCpHeciSvc.exe [284144 2016-10-27] (Intel Corporation)
S3 cplspcon; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\IntelCpHDCPSvc.exe [462832 2016-10-27] (Intel Corporation)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
R2 hmevpnsvc; C:\Program Files (x86)\hide.me VPN\hidemesvc.exe [139472 2017-05-18] (eVenture Limited)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\igfxCUIService.exe [324592 2016-10-27] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [630048 2016-10-14] (Intel(R) Corporation)
R3 Intel(R) Online Connect; C:\Program Files\Intel\Intel(R) Online Connect\ioc.exe [25312 2016-11-02] (Intel Corporation)
S2 Intel(R) Online Connect Helper; C:\Program Files\Intel\Intel(R) Online Connect\iocHelperService.exe [34528 2016-11-02] (Intel Corporation)
S3 Intel(R) Online Connect Software Asset Manager; C:\Program Files (x86)\Intel\Intel(R) Online Connect Access\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [18152 2016-10-15] (Intel Corporation)
R2 Intel(R) TechnologyAccessLegacyCSLoader; C:\Program Files\Intel\Intel(R) Online Connect Access\LegacyCsLoaderService.exe [173288 2016-10-18] (Intel(R) Corporation)
R2 Intel(R) TechnologyAccessService; C:\Program Files\Intel\Intel(R) Online Connect Access\IntelTechnologyAccessService.exe [496872 2016-10-18] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [177440 2016-11-09] (Intel Corporation)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [2385832 2017-04-30] (Maxthon)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-05-03] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-11-20] (Microsoft Corporation)
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [745664 2016-01-12] (@ByELDI) [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10884848 2017-05-23] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)
S2 CG6Service; "C:\Program Files\CyberGhost 6\CyberGhost.Service.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2015-05-09] ()
S3 CH341SER_A64; C:\WINDOWS\System32\Drivers\CH341S64.SYS [59904 2015-02-06] (www.winchiphead.com)
R3 ElcMouLFlt; C:\WINDOWS\System32\drivers\ElcMouLFlt.sys [27128 2017-04-30] (ELECOM)
R3 ElcMouUFlt; C:\WINDOWS\System32\drivers\ElcMouUFlt.sys [26104 2017-04-30] (ELECOM)
S3 igfx; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_caf762663b02849b\igdkmd64.sys [11033568 2016-10-27] (Intel Corporation)
R1 MpKsl0e06ac36; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{27739550-BE80-4E84-ABC2-F5F4D03FFBFC}\MpKsl0e06ac36.sys [44928 2017-06-12] (Microsoft Corporation)
R1 MpKsl3efd60c8; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{52AE8A9F-3B46-4E19-A2E4-DDF1A661CA5A}\MpKsl3efd60c8.sys [44928 2017-06-11] (Microsoft Corporation)
R1 ndisrd; C:\WINDOWS\system32\DRIVERS\ndisrfl.sys [59792 2016-09-14] (Intel Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_a2b0acab06663645\nvlddmkm.sys [14456944 2017-05-02] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-05-03] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48248 2017-05-03] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57976 2017-05-03] (NVIDIA Corporation)
S3 ptun0901; C:\WINDOWS\System32\drivers\ptun0901.sys [27136 2016-06-15] (The OpenVPN Project)
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
R3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2017-04-30] ()
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S3 hmatap; \SystemRoot\System32\drivers\hmatap.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-06-12 18:28 - 2017-06-12 18:29 - 00020309 _____ C:\Users\Kris\Desktop\FRST.txt
2017-06-12 18:28 - 2017-06-12 18:28 - 02438656 _____ (Farbar) C:\Users\Kris\Desktop\FRST64.exe
2017-06-12 18:28 - 2017-06-12 18:28 - 00000000 ____D C:\FRST
2017-06-12 15:26 - 2017-06-12 15:26 - 00069632 _____ C:\Users\Kris\Documents\Problem.evtx
2017-06-11 22:45 - 2017-06-11 22:56 - 01048205 _____ C:\Users\Kris\Desktop\Test.exe
2017-06-11 13:21 - 2017-06-11 13:21 - 00036510 _____ C:\Users\Kris\Downloads\Кит комплект сензор мелачка – 20000230 _ Milov.html
2017-06-11 13:21 - 2017-06-11 13:21 - 00028597 _____ C:\Users\Kris\Downloads\КОМБИНА БАР ЕООД __ Сензор ХОЛ за обороти хоризонт. мелачка Saeco2.html
2017-06-11 13:21 - 2017-06-11 13:21 - 00000000 ____D C:\Users\Kris\Downloads\КОМБИНА БАР ЕООД __ Сензор ХОЛ за обороти хоризонт. мелачка Saeco2_files
2017-06-11 13:21 - 2017-06-11 13:21 - 00000000 ____D C:\Users\Kris\Downloads\Кит комплект сензор мелачка – 20000230 _ Milov_files
2017-06-11 13:20 - 2017-06-11 13:20 - 00028580 _____ C:\Users\Kris\Downloads\КОМБИНА БАР ЕООД __ Сензор ХОЛ за обороти хоризонт. мелачка Saeco.html
2017-06-11 13:20 - 2017-06-11 13:20 - 00000000 ____D C:\Users\Kris\Downloads\КОМБИНА БАР ЕООД __ Сензор ХОЛ за обороти хоризонт. мелачка Saeco_files
2017-06-05 22:43 - 2017-06-11 22:56 - 00000000 ____D C:\Users\Kris\AppData\Roaming\CodeBlocks
2017-06-05 22:42 - 2017-06-05 22:43 - 00000000 ____D C:\Users\Kris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CodeBlocks
2017-06-05 22:42 - 2017-06-05 22:43 - 00000000 ____D C:\Program Files (x86)\CodeBlocks
2017-06-05 22:42 - 2017-06-05 22:42 - 00001164 _____ C:\Users\Kris\Documents\CodeBlocks.lnk
2017-06-05 22:42 - 2017-06-05 22:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks
2017-06-01 14:43 - 2017-06-01 14:43 - 00000000 ____D C:\Users\Kris\Documents\FeedbackHub
2017-05-28 22:52 - 2017-06-07 22:38 - 00000000 ____D C:\Users\Kris\Desktop\DOB LOVE
2017-05-28 16:49 - 2017-05-28 16:49 - 00000000 ____D C:\Program Files (x86)\hide.me VPN
2017-05-28 16:48 - 2017-05-28 22:21 - 00000000 ____D C:\Users\Kris\AppData\Roaming\Hide.me
2017-05-28 16:48 - 2017-05-28 16:49 - 00001098 _____ C:\Users\Kris\Documents\hide.me VPN.lnk
2017-05-28 16:48 - 2017-05-28 16:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hide.me VPN
2017-05-28 16:47 - 2017-05-28 16:47 - 06289296 _____ (eVenture Limited ) C:\Users\Kris\Downloads\Hide.me-Setup-1.2.13.exe
2017-05-28 12:35 - 2017-05-28 12:35 - 00002075 _____ C:\Users\Kris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberGhost 6.lnk
2017-05-28 12:34 - 2017-05-28 16:07 - 00000000 ____D C:\Program Files\CyberGhost 6
2017-05-28 12:34 - 2017-05-28 12:35 - 00000000 ____D C:\Users\Kris\AppData\Local\CyberGhost
2017-05-28 12:34 - 2017-05-28 12:34 - 00000000 ____D C:\Program Files\TAP-Windows
2017-05-28 12:10 - 2017-05-28 12:10 - 00000000 ____D C:\Users\Kris\Documents\My Cheat Tables
2017-05-26 15:28 - 2017-05-27 16:05 - 00000000 ____D C:\Users\Kris\Documents\VirtualDJ
2017-05-26 15:28 - 2017-05-26 15:28 - 00001038 _____ C:\Users\Kris\Documents\VirtualDJ PRO Full.lnk
2017-05-26 15:28 - 2017-05-26 15:28 - 00000000 ____D C:\Users\Kris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2017-05-26 15:28 - 2017-05-26 15:28 - 00000000 ____D C:\Program Files (x86)\VirtualDJ
2017-05-25 23:27 - 2017-05-25 23:27 - 00002007 _____ C:\Users\Kris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Turn Monitor Off.lnk
2017-05-25 23:21 - 2017-05-25 23:27 - 00001783 _____ C:\Users\Kris\Documents\Turn Monitor Off.lnk
2017-05-25 23:20 - 2017-05-25 23:20 - 00000000 ____D C:\temp
2017-05-25 23:20 - 2016-05-23 09:44 - 00116736 _____ (NirSoft) C:\WINDOWS\nircmd.exe
2017-05-25 03:42 - 2017-05-25 03:42 - 00001256 _____ C:\Users\Kris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update and Privacy Settings.lnk
2017-05-25 03:42 - 2017-05-25 03:42 - 00000000 ____D C:\Users\Kris\AppData\Local\UNP
2017-05-25 03:32 - 2017-05-25 03:33 - 00000000 ____D C:\Program Files\UNP
2017-05-25 03:32 - 2017-05-25 03:32 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-05-20 22:57 - 2017-05-20 22:57 - 00000000 ____D C:\Users\Kris\AppData\Local\Macromedia
2017-05-20 22:50 - 2017-06-11 22:11 - 00000000 ____D C:\Users\Kris\AppData\LocalLow\Mozilla
2017-05-20 22:50 - 2017-05-20 22:55 - 00000000 ____D C:\Users\Kris\AppData\Local\Mozilla
2017-05-20 22:50 - 2017-05-20 22:50 - 00001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-05-20 22:50 - 2017-05-20 22:50 - 00001220 _____ C:\Users\Kris\Documents\Mozilla Firefox.lnk
2017-05-20 22:50 - 2017-05-20 22:50 - 00000000 ____D C:\Users\Kris\AppData\Roaming\Mozilla
2017-05-20 22:50 - 2017-05-20 22:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-05-20 22:50 - 2017-05-20 22:50 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-05-20 20:26 - 2017-05-20 20:26 - 00000000 ____D C:\Users\Kris\AppData\LocalLow\Temp
2017-05-17 17:39 - 2017-05-17 17:39 - 00000000 ____D C:\Users\Kris\Documents\AutomaticSolution Software
2017-05-17 17:12 - 2017-05-17 17:12 - 00000000 ____D C:\Users\Kris\Documents\Lightshot
2017-05-16 16:40 - 2017-05-16 16:40 - 00004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-16 16:40 - 2017-05-16 16:40 - 00001489 _____ C:\Users\Kris\Documents\GeForce Experience.lnk
2017-05-16 16:39 - 2017-05-03 23:21 - 00175736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-05-16 16:39 - 2017-05-03 23:21 - 00143480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-05-15 22:32 - 2017-05-15 22:32 - 00110144 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2017-05-15 22:32 - 2017-05-15 22:32 - 00000000 ____D C:\Users\Kris\AppData\Roaming\Sun
2017-05-15 22:32 - 2017-05-15 22:32 - 00000000 ____D C:\Users\Kris\AppData\LocalLow\Sun
2017-05-15 22:32 - 2017-05-15 22:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-05-15 22:31 - 2017-05-15 22:31 - 00000000 ____D C:\Program Files\Java
2017-05-15 22:27 - 2017-05-15 22:36 - 00000000 ____D C:\Users\Kris\AppData\Roaming\.minecraft
2017-05-15 22:27 - 2017-05-15 22:28 - 00000000 ____D C:\Program Files (x86)\Minecraft
2017-05-15 22:27 - 2017-05-15 22:27 - 00001030 _____ C:\Users\Kris\Documents\Minecraft.lnk
2017-05-15 22:27 - 2017-05-15 22:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
2017-05-15 10:26 - 2017-06-11 22:53 - 00000000 ____D C:\Users\Kris\Documents\Visual Studio 2012
2017-05-15 10:25 - 2017-05-15 10:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 5 SDK
2017-05-15 10:25 - 2017-05-15 10:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 4 SDK
2017-05-15 10:25 - 2017-05-15 10:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-05-15 10:25 - 2017-05-15 10:25 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2017-05-15 10:25 - 2017-05-15 10:25 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2017-05-15 10:25 - 2017-05-15 10:25 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-05-15 10:24 - 2017-05-15 10:24 - 00002177 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\ProgramData\Windows App Certification Kit
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\ProgramData\PreEmptive Solutions
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\Program Files\IIS Express
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\Program Files\Application Verifier
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Web Tools
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\Program Files (x86)\IIS Express
2017-05-15 10:24 - 2017-05-15 10:24 - 00000000 ____D C:\Program Files (x86)\Application Verifier
2017-05-15 10:23 - 2017-05-15 10:23 - 00000000 ____D C:\WINDOWS\SysWOW64\1033
2017-05-15 10:23 - 2017-05-15 10:23 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2017-05-15 10:23 - 2017-05-15 10:23 - 00000000 ____D C:\Program Files (x86)\NuGet
2017-05-15 10:23 - 2017-05-15 10:23 - 00000000 ____D C:\Program Files (x86)\Microsoft WCF Data Services
2017-05-15 10:23 - 2017-05-15 10:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Help Viewer
2017-05-15 10:23 - 2017-05-15 10:23 - 00000000 ____D C:\Program Files (x86)\HTML Help Workshop
2017-05-15 10:22 - 2017-05-15 10:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 11.0
2017-05-15 10:22 - 2017-05-15 10:25 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2017-05-15 10:22 - 2017-05-15 10:25 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2017-05-15 10:22 - 2017-05-15 10:25 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2017-05-15 10:22 - 2017-05-15 10:23 - 00000000 ____D C:\WINDOWS\system32\1033
2017-05-15 10:22 - 2017-05-15 10:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Studio 2012
2017-05-15 10:22 - 2017-05-15 10:22 - 00000000 ____D C:\WINDOWS\symbols
2017-05-15 10:22 - 2017-05-15 10:22 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 11.0
2017-05-14 22:40 - 2017-06-04 18:44 - 00000000 ____D C:\Users\Kris\AppData\Local\CrashDumps
2017-05-14 22:14 - 2017-06-09 17:11 - 00000000 ____D C:\Users\Kris\AppData\LocalLow\uTorrent
2017-05-14 21:26 - 2017-05-28 13:18 - 00000000 ____D C:\Users\Kris\Documents\Audition

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-06-12 18:23 - 2017-04-30 08:22 - 00000000 ____D C:\Users\Kris\AppData\Roaming\Skype
2017-06-12 18:17 - 2017-04-30 21:10 - 00000000 ____D C:\Users\Kris\AppData\Roaming\TS3Client
2017-06-12 14:34 - 2017-04-30 10:47 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-12 14:31 - 2017-04-30 11:13 - 00000000 ___RD C:\Users\Kris\Google Drive
2017-06-12 07:19 - 2016-11-20 21:41 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-06-12 04:51 - 2016-11-20 21:51 - 01157310 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-06-12 04:45 - 2016-11-20 21:41 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-12 04:44 - 2017-04-30 10:48 - 00000000 ____D C:\Users\Kris
2017-06-11 21:06 - 2017-04-30 14:34 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-06-11 21:06 - 2017-04-30 07:53 - 00000000 ____D C:\ProgramData\Skype
2017-06-11 21:00 - 2017-04-30 08:47 - 00000000 ____D C:\Users\Kris\AppData\Roaming\AIMP
2017-06-11 13:30 - 2016-07-16 14:47 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2017-06-09 23:22 - 2016-07-16 14:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-09 23:22 - 2016-07-16 14:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-09 23:16 - 2017-04-30 11:14 - 00000000 ____D C:\Users\Kris\AppData\Roaming\uTorrent
2017-06-09 23:16 - 2016-07-16 09:04 - 00262144 _____ C:\WINDOWS\system32\config\BBI
2017-06-09 21:15 - 2017-05-01 00:05 - 00000000 ____D C:\Users\Kris\AppData\Local\PokerStars.BG
2017-06-09 20:46 - 2017-05-03 21:30 - 00000000 ____D C:\Users\Kris\AppData\Roaming\vlc
2017-06-09 17:01 - 2016-07-16 14:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-08 15:28 - 2016-07-16 14:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-06 16:35 - 2017-05-03 15:19 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-06-05 15:23 - 2017-05-03 15:19 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-06-01 16:40 - 2017-04-30 15:53 - 00000132 _____ C:\Users\Kris\AppData\Roaming\Adobe PNG Format CS6 Prefs
2017-05-31 16:12 - 2017-04-30 07:57 - 00565416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-05-31 15:24 - 2017-05-02 21:49 - 00003942 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1493750990
2017-05-31 15:24 - 2017-05-02 21:49 - 00001078 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2017-05-31 15:24 - 2017-05-02 21:49 - 00000000 ____D C:\Program Files\Opera
2017-05-28 16:45 - 2017-04-30 08:20 - 00000000 ____D C:\Program Files (x86)\OpenVPN Technologies
2017-05-28 16:07 - 2016-11-20 21:40 - 04899032 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-05-28 12:35 - 2017-04-30 07:04 - 00000000 ____D C:\Users\Kris\AppData\Local\VirtualStore
2017-05-28 12:34 - 2017-04-30 08:18 - 00000000 ____D C:\Program Files (x86)\HMA! Pro VPN
2017-05-28 12:34 - 2016-07-16 14:45 - 00000000 ____D C:\WINDOWS\INF
2017-05-28 01:04 - 2016-07-16 14:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-05-28 01:03 - 2016-07-16 14:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-05-27 12:16 - 2017-04-29 23:06 - 00000000 ____D C:\Users\Kris\AppData\Local\MicrosoftEdge
2017-05-23 20:19 - 2017-04-30 07:56 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-23 20:18 - 2017-04-30 07:56 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-20 22:57 - 2017-04-30 11:21 - 00000000 ____D C:\Users\Kris\AppData\Local\Adobe
2017-05-17 07:10 - 2017-05-02 21:22 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-16 17:21 - 2017-05-01 00:04 - 00000000 ____D C:\Program Files (x86)\PokerStars.BG
2017-05-16 16:56 - 2017-04-30 14:45 - 00000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2017-05-16 16:40 - 2017-04-30 10:50 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-16 16:40 - 2017-04-30 10:50 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-16 16:40 - 2017-04-30 10:50 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-16 16:40 - 2017-04-30 10:50 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-16 16:40 - 2017-04-30 10:50 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-16 16:40 - 2017-04-30 10:50 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-16 16:40 - 2017-04-30 10:50 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-05-16 16:40 - 2017-04-30 10:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-05-16 16:40 - 2017-04-30 10:47 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-05-16 16:40 - 2017-04-30 10:47 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-05-15 12:02 - 2016-07-16 14:47 - 00000000 ____D C:\WINDOWS\rescache
2017-05-15 10:25 - 2016-07-16 14:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-05-15 10:24 - 2017-04-30 12:48 - 00000000 ____D C:\Program Files\MSBuild
2017-05-15 10:23 - 2017-04-30 12:48 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-05-15 10:22 - 2017-04-30 07:21 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-15 10:22 - 2016-07-16 14:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-13 21:52 - 2017-05-12 15:24 - 00000000 ____D C:\Users\Kris\Documents\Sound recordings

==================== Files in the root of some directories =======

2017-04-30 15:53 - 2017-06-01 16:40 - 0000132 _____ () C:\Users\Kris\AppData\Roaming\Adobe PNG Format CS6 Prefs
2017-04-30 11:30 - 2017-04-30 11:30 - 0000003 _____ () C:\Users\Kris\AppData\Local\updater.log
2017-04-30 11:30 - 2017-04-30 11:30 - 0000425 _____ () C:\Users\Kris\AppData\Local\UserProducts.xml
2017-04-30 10:47 - 2017-04-30 10:47 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
2017-04-30 12:38 - 2017-04-30 12:38 - 49529576 _____ (FinalWire Ltd.                                              ) C:\Users\Kris\AppData\Local\Temp\aida64extreme590.exe
2017-04-30 11:17 - 2017-04-30 11:17 - 93992520 _____ () C:\Users\Kris\AppData\Local\Temp\arduino-1.8.2-windows.exe
2017-05-28 12:34 - 2017-05-28 12:34 - 16086472 _____ (CyberGhost S.R.L.                                           ) C:\Users\Kris\AppData\Local\Temp\CG_6.0.526951.exe
2017-05-02 21:22 - 2017-05-02 21:22 - 1130328 _____ (Google Inc.) C:\Users\Kris\AppData\Local\Temp\ChromeSetup.exe
2017-06-05 22:42 - 2017-06-05 22:42 - 83783938 _____ (The Code::Blocks Team) C:\Users\Kris\AppData\Local\Temp\codeblocks-16.01mingw-setup.exe
2017-04-30 12:13 - 2017-04-30 12:13 - 1704136 _____ (                                                            ) C:\Users\Kris\AppData\Local\Temp\cpu-z_1.79-en.exe
2017-04-30 14:36 - 2017-04-30 14:36 - 0292184 _____ (Microsoft Corporation) C:\Users\Kris\AppData\Local\Temp\dxwebsetup.exe
2017-05-20 22:50 - 2017-05-20 22:50 - 0246232 _____ (Mozilla) C:\Users\Kris\AppData\Local\Temp\Firefox Setup Stub 53.0.3.exe
2017-06-12 18:28 - 2017-06-12 18:28 - 2438656 _____ (Farbar) C:\Users\Kris\AppData\Local\Temp\FRST64.exe
2017-04-30 11:11 - 2017-04-30 11:11 - 1130328 _____ (Google Inc.) C:\Users\Kris\AppData\Local\Temp\googledrivesync.exe
2017-05-19 16:35 - 2017-05-19 16:35 - 0867241 _____ () C:\Users\Kris\AppData\Local\Temp\GSAutoClicker-Setup(1).exe
2017-05-17 17:39 - 2017-05-17 17:39 - 0867241 _____ () C:\Users\Kris\AppData\Local\Temp\GSAutoClicker-Setup.exe
2017-05-28 16:49 - 2017-05-28 16:49 - 6289296 _____ (eVenture Limited                                            ) C:\Users\Kris\AppData\Local\Temp\Hide.me-Setup-1.2.13.exe
2017-05-28 12:33 - 2017-05-28 12:33 - 7567088 _____ (Privax Ltd) C:\Users\Kris\AppData\Local\Temp\HMA-Pro-VPN-3.4.6.1-install(1).exe
2017-05-28 12:32 - 2017-05-28 12:32 - 7567088 _____ (Privax Ltd) C:\Users\Kris\AppData\Local\Temp\HMA-Pro-VPN-3.4.6.1-install.exe
2017-05-15 22:32 - 2017-05-15 22:32 - 0019968 ____N (Red Hat®, Inc.) C:\Users\Kris\AppData\Local\Temp\jansi-64-git-Spigot-c6871e2-0cd0397-2161919650563422529.dll
2017-05-15 22:36 - 2017-05-15 22:36 - 0019968 ____N (Red Hat®, Inc.) C:\Users\Kris\AppData\Local\Temp\jansi-64-git-Spigot-c6871e2-0cd0397-6343540281877952254.dll
2017-05-15 22:31 - 2017-05-15 22:31 - 65659968 _____ (Oracle Corporation) C:\Users\Kris\AppData\Local\Temp\jre-8u131-windows-x64.exe
2017-05-08 18:57 - 2017-05-08 18:57 - 32529256 _____ (Riot Games) C:\Users\Kris\AppData\Local\Temp\LeagueofLegends_EUNE_Installer_2016_11_10.exe
2017-04-30 11:19 - 2017-04-30 11:19 - 2982992 _____ () C:\Users\Kris\AppData\Local\Temp\npp.7.3.3.Installer.exe
2017-04-30 07:44 - 2017-04-20 03:18 - 0754352 _____ (NVIDIA Corporation) C:\Users\Kris\AppData\Local\Temp\nvSCPAPI.dll
2017-04-30 07:44 - 2017-04-20 03:18 - 0867968 _____ (NVIDIA Corporation) C:\Users\Kris\AppData\Local\Temp\nvSCPAPI64.dll
2017-05-07 18:20 - 2017-04-20 03:18 - 0367736 _____ (NVIDIA Corporation) C:\Users\Kris\AppData\Local\Temp\nvStInst.exe
2017-05-02 21:49 - 2017-05-02 21:49 - 1186096 _____ (Opera Software) C:\Users\Kris\AppData\Local\Temp\OperaSetup.exe
2017-05-01 00:03 - 2017-05-01 00:04 - 108547352 _____ (Rational Intellectual Holdings Ltd.) C:\Users\Kris\AppData\Local\Temp\PokerStarsInstallBG(1).exe
2017-04-30 22:24 - 2017-04-30 22:24 - 108547360 _____ (Rational Intellectual Holdings Ltd.) C:\Users\Kris\AppData\Local\Temp\PokerStarsInstallBG.exe
2017-05-28 12:37 - 2017-05-28 12:37 - 30901272 _____ (OpenVPN Technologies) C:\Users\Kris\AppData\Local\Temp\privatetunnel-win-2.8.exe
2017-04-30 11:30 - 2017-04-30 11:30 - 2732544 _____ (Skillbrains                                                 ) C:\Users\Kris\AppData\Local\Temp\setup-lightshot.exe
2017-04-30 14:33 - 2017-04-30 14:33 - 1631704 _____ (Skype Technologies S.A.) C:\Users\Kris\AppData\Local\Temp\SkypeSetup.exe
2017-05-15 22:32 - 2017-05-15 22:32 - 0515584 _____ () C:\Users\Kris\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll
2017-04-30 21:10 - 2017-04-30 21:10 - 77604984 _____ (TeamSpeak Systems GmbH) C:\Users\Kris\AppData\Local\Temp\TeamSpeak3-Client-win64-3.1.4(1).exe
2017-04-30 16:52 - 2017-04-30 16:52 - 77604984 _____ (TeamSpeak Systems GmbH) C:\Users\Kris\AppData\Local\Temp\TeamSpeak3-Client-win64-3.1.4.exe
2017-05-03 15:19 - 2017-05-03 15:19 - 14725904 _____ (TeamViewer GmbH) C:\Users\Kris\AppData\Local\Temp\TeamViewer_Setup.exe
2017-04-30 11:14 - 2017-04-30 11:14 - 2403520 _____ (BitTorrent Inc.) C:\Users\Kris\AppData\Local\Temp\uTorrent.exe
2017-04-30 14:33 - 2017-04-30 14:33 - 14456872 _____ (Microsoft Corporation) C:\Users\Kris\AppData\Local\Temp\vc_redist.x86.exe
2017-04-30 22:49 - 2017-04-30 22:49 - 3003896 _____ () C:\Users\Kris\AppData\Local\Temp\XMouseButtonControlSetup.2.15.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-06-05 23:25

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-06-2017
Ran by Kris (12-06-2017 18:29:38)
Running from C:\Users\Kris\Desktop
Windows 10 Pro Version 1607 (X64) (2017-04-30 07:50:59)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1594962750-1340225539-4068360994-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1594962750-1340225539-4068360994-503 - Limited - Disabled)
Guest (S-1-5-21-1594962750-1340225539-4068360994-501 - Limited - Disabled)
Kris (S-1-5-21-1594962750-1340225539-4068360994-1001 - Administrator - Enabled) => C:\Users\Kris

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\...\uTorrent) (Version: 3.5.0.43804 - BitTorrent Inc.)
Adobe Audition CC 2015.2 (HKLM-x32\...\AUDT_9_2_1) (Version: 9.2.1 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Adobe Flash Player 25 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
AIDA64 Extreme v5.90 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 5.90 - FinalWire Ltd.)
AIMP (HKLM-x32\...\AIMP) (Version: v4.10.1831, 31.08.2016 - AIMP DevTeam)
Ansel (Version: 382.05 - NVIDIA Corporation) Hidden
Arduino (HKLM-x32\...\Arduino) (Version: 1.8.2 - Arduino LLC)
Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio 2012 ENU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Camtasia Studio 8 (HKLM-x32\...\{DB93E2C2-851F-44B2-B09C-351D2C624AE1}) (Version: 8.0.4.1060 - TechSmith Corporation)
CodeBlocks (HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\...\CodeBlocks) (Version: 16.01 - The Code::Blocks Team)
CPUID CPU-Z 1.79 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
DoNotSpy10 (HKLM-x32\...\{32D066BD-F94C-4948-8FA8-84653EE9617E}_is1) (Version: 2.0 - pXc-coding.com)
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden
DTSStudioSoundGuiPluginInstaller (HKLM-x32\...\{83D9B703-6B52-4D06-B316-C51F239C8565}) (Version: 1.00.1900 - DTS, Inc.)
Entity Framework Designer for Visual Studio 2012 - enu (HKLM-x32\...\{0A1A1D48-DB23-443A-BC7B-49255D138020}) (Version: 11.1.20702.00 - Microsoft Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.)
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
hide.me VPN 1.2.13 (HKLM-x32\...\{0E00BDA5-7998-4889-BE4B-39A4BBD2EDFB}_is1) (Version: 1.2.13 - eVenture Limited)
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
Intel(R) Chipset Device Software (x32 Version: 10.1.1.38 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1039 - Intel Corporation)
Intel(R) Network Connections 20.2.4001.0 (HKLM\...\PROSetDX) (Version: 20.2.4001.0 - Intel)
Intel(R) Online Connect Software Asset Manager (x32 Version: 3.4.2095 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 21.20.16.4541 - Intel Corporation)
Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version:  - )
League of Legends (HKLM-x32\...\League of Legends 4.2.1) (Version: 4.2.1 - Riot Games)
League of Legends (x32 Version: 4.2.1 - Riot Games) Hidden
Lightshot-5.4.0.10 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.10 - Skillbrains)
LocalESPC (x32 Version: 8.59.25584 - Microsoft Corporation) Hidden
LocalESPCui for en-us (x32 Version: 8.59.25584 - Microsoft) Hidden
Maxthon Cloud Browser (HKLM-x32\...\Maxthon3) (Version: 4.9.4.3000 - Maxthon International Limited)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{5CBFF3F3-2D40-34EE-BCA5-A95BC19E400D}) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{1948E039-EC79-4591-951D-9867A8C14C90}) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft ASP.NET MVC 3 (HKLM-x32\...\{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}) (Version: 3.0.20105.0 - Microsoft Corporation)
Microsoft ASP.NET Web Pages (HKLM-x32\...\{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}) (Version: 1.0.20105.0 - Microsoft Corporation)
Microsoft Help Viewer 2.0 (HKLM-x32\...\Microsoft Help Viewer 2.0) (Version: 2.0.50727 - Microsoft Corporation)
Microsoft Office 2010 Service Pack 1 (SP1) (HKLM\...\{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}) (Version:  - Microsoft)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.10411.0 - Microsoft Corporation)
Microsoft Silverlight 4 SDK (HKLM-x32\...\{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM\...\{36E619BC-A234-4EC3-849B-779A7C865A45}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{FA0A244E-F3C2-4589-B42A-3D522DE79A42}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL Compiler Service  (HKLM\...\{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (11.1.20627.00) (HKLM-x32\...\{FA804794-2CCB-4301-954F-2C2894698876}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00) (HKLM-x32\...\{790E9425-8570-493F-9AE7-81AFC9E46930}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{A47FD1BF-A815-4A76-BE65-53A15BD5D25D}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{F1949145-EB64-4DE7-9D81-E6D27937146C}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31125 - Microsoft Corporation)
Microsoft Visual Studio Professional 2012 (HKLM-x32\...\{17c2e197-cf26-443b-8beb-53151940df3f}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Web Deploy dbSqlPackage Provider - enu (HKLM-x32\...\{E4C33F5B-1B2F-466E-957E-B274F08151A0}) (Version: 10.3.20225.0 - Microsoft Corporation)
Microsoft Web Platform Installer 4.0 (HKLM\...\{E2B8249D-895C-4685-8C83-00F3B1A13028}) (Version: 4.0.1622 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Mozilla Firefox 53.0.3 (x86 bg) (HKLM-x32\...\Mozilla Firefox 53.0.3 (x86 bg)) (Version: 53.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.3 - Mozilla)
MSI Afterburner 4.3.0 (HKLM-x32\...\Afterburner) (Version: 4.3.0 - MSI Co., LTD)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.3 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 382.05 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.6.0.74 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.6.0.74 - NVIDIA Corporation)
NVIDIA Graphics Driver 382.05 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 382.05 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.26 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.17.0329 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0329 - NVIDIA Corporation)
NvNodejs (Version: 3.6.0.74 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 2.4.10.0 - NVIDIA Corporation) Hidden
NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
Opera Stable 45.0.2552.888 (HKLM-x32\...\Opera 45.0.2552.888) (Version: 45.0.2552.888 - Opera Software)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
PokerStars.bg (HKLM-x32\...\PokerStars.bg) (Version:  - PokerStars.bg)
PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7910 - Realtek Semiconductor Corp.)
RivaTuner Statistics Server 6.5.0 (HKLM-x32\...\RTSS) (Version: 6.5.0 - Unwinder)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games)
SHIELD Streaming (Version: 7.1.0370 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.6.0.74 - NVIDIA Corporation) Hidden
Skype™ 7.36 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.36.101 - Skype Technologies S.A.)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.1.4 - TeamSpeak Systems GmbH)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.78313 - TeamViewer)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.01 - Ghisler Software GmbH)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
VirtualDJ PRO Full (HKLM-x32\...\{4769E972-2E92-49C5-B6F9-465EFD0C4D94}) (Version: 7.0.5 - Atomix Productions)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.)
WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{3A523AF9-D32F-4C85-8388-0335731F3405}) (Version: 4.1.61829.0 - Microsoft Corporation)
Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation)
WinRAR 5.50 beta 1 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.1 - win.rar GmbH)
X-Mouse Button Control 2.15 (HKLM-x32\...\X-Mouse Button Control) (Version: 2.15 - Highresolution Enterprises)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\AutoKMS.job => C:\WINDOWS\AutoKMS.exe
Task: C:\WINDOWS\Tasks\update-S-1-5-21-1594962750-1340225539-4068360994-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Kris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\Online Help.lnk -> hxxp://www.virtualdj.com/wiki
Shortcut: C:\Users\Kris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ\www.virtualdj.com.lnk -> hxxp://www.virtualdj.com

==================== Loaded Modules (Whitelisted) ==============

2017-04-30 08:49 - 2015-05-09 00:26 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2017-04-30 08:49 - 2014-04-25 00:29 - 01360016 _____ () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
2016-10-18 06:00 - 2016-10-18 06:00 - 00107752 _____ () C:\Program Files\Intel\Intel(R) Online Connect Access\libglog.dll
2016-10-18 06:00 - 2016-10-18 06:00 - 00412904 _____ () C:\Program Files\Intel\Intel(R) Online Connect Access\JsonCpp.dll
2017-04-30 07:35 - 2017-05-03 23:21 - 01267320 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-11-02 03:18 - 2016-11-02 03:18 - 00253664 _____ () C:\Program Files\Intel\Intel(R) Online Connect\CSLibWrapper.dll
2016-07-16 14:42 - 2016-07-16 14:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-05-10 20:54 - 2017-04-28 03:49 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2017-04-30 10:47 - 2017-05-01 23:51 - 00133752 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-04-30 10:52 - 2017-04-30 10:52 - 00959168 _____ () C:\Users\Kris\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64\ClientTelemetry.dll
2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 15:23 - 2010-10-20 15:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2017-03-08 05:42 - 2017-03-08 05:42 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2016-11-20 21:11 - 2016-11-20 21:11 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-04-30 12:53 - 2017-03-04 09:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-06-08 15:28 - 2017-06-08 15:28 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-06-08 15:28 - 2017-06-08 15:28 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-06-08 15:28 - 2017-06-08 15:28 - 43318784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-06-08 15:28 - 2017-06-08 15:28 - 02427904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\skypert.dll
2017-04-30 12:52 - 2017-03-04 09:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-04-30 12:52 - 2017-03-04 09:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-04-30 12:52 - 2017-03-04 09:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-05-10 20:54 - 2017-04-28 02:36 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-05-10 20:54 - 2017-04-28 02:37 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-05-31 15:24 - 2017-05-31 15:24 - 90985048 _____ () C:\Program Files\Opera\45.0.2552.888\opera_browser.dll
2017-05-31 15:24 - 2017-05-31 15:23 - 03949144 _____ () C:\Program Files\Opera\45.0.2552.888\libglesv2.dll
2017-05-31 15:24 - 2017-05-31 15:23 - 00101464 _____ () C:\Program Files\Opera\45.0.2552.888\libegl.dll
2017-04-12 13:46 - 2017-04-12 13:46 - 00176408 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll
2017-03-13 19:37 - 2017-03-13 19:37 - 00020248 _____ () C:\Program Files\TeamSpeak 3 Client\libEGL.DLL
2017-03-13 19:37 - 2017-03-13 19:37 - 01975064 _____ () C:\Program Files\TeamSpeak 3 Client\libGLESv2.dll
2017-04-12 13:46 - 2017-04-12 13:46 - 00107288 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll
2017-04-12 13:46 - 2017-04-12 13:46 - 00128280 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll
2017-04-30 21:10 - 2017-05-04 17:21 - 00152064 _____ () C:\Users\Kris\AppData\Roaming\TS3Client\plugins\gamepad_joystick_win64.dll
2017-04-30 21:10 - 2017-04-30 21:11 - 00345880 _____ () C:\Users\Kris\AppData\Roaming\TS3Client\plugins\clientquery_plugin_win64.dll
2017-06-05 21:19 - 2017-06-05 21:20 - 00020480 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2017-06-05 21:19 - 2017-06-05 21:20 - 27430400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-06-05 21:19 - 2017-06-05 21:20 - 00460288 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll
2017-06-05 21:19 - 2017-06-05 21:20 - 02275328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2017-06-05 21:19 - 2017-06-05 21:20 - 03139496 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2017-06-05 21:19 - 2017-06-05 21:20 - 00046080 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
2017-04-30 07:47 - 2017-04-30 07:48 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll
2017-06-05 21:19 - 2017-06-05 21:20 - 00900096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2017-05-09 16:18 - 2017-05-09 16:18 - 01062400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll
2017-04-30 07:47 - 2017-04-30 07:48 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.524.10020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2017-05-23 07:14 - 2017-05-23 07:14 - 03918848 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1705.1301.0_x64__8wekyb3d8bbwe\Calculator.exe
2017-04-30 08:49 - 2017-06-12 04:45 - 00039208 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2017-04-30 08:49 - 2015-05-09 00:26 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2016-11-09 05:40 - 2016-11-09 05:40 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2017-04-30 07:35 - 2017-05-03 23:21 - 01040504 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-06-12 14:31 - 2017-06-12 14:31 - 00098816 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32api.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00110080 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\pywintypes27.dll
2017-06-12 14:31 - 2017-06-12 14:31 - 00364544 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\pythoncom27.dll
2017-06-12 14:31 - 2017-06-12 14:31 - 00320512 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32com.shell.shell.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00914432 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\_hashlib.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 01176576 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\wx._core_.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00806400 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\wx._gdi_.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00816128 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\wx._windows_.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 01067008 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\wx._controls_.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00733184 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\wx._misc_.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00682496 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\pysqlite2._sqlite.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00088064 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\_ctypes.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00686080 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\unicodedata.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00119808 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32file.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00108544 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32security.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00007168 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\hashobjs_ext.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00017920 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\thumbnails_ext.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00088064 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\usb_ext.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00012800 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\common.time34.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00018432 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32event.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00167936 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32gui.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00046080 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\_socket.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 01303552 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\_ssl.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00128512 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\_elementtree.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00127488 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\pyexpat.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00038912 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32inet.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00036864 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\_psutil_windows.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00524248 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\windows._lib_cacheinvalidation.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00011264 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32crypt.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00123392 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\wx._wizard.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00077312 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\wx._html2.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00027648 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\_multiprocessing.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00020480 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\_yappi.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00035840 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32process.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00078848 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\wx._animate.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00024064 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32pipe.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00010240 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\select.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00025600 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32pdh.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00017408 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32profile.pyd
2017-06-12 14:31 - 2017-06-12 14:31 - 00022528 ____R () C:\Users\Kris\AppData\Local\Temp\_MEI77162\win32ts.pyd
2017-04-26 15:19 - 2017-04-26 15:19 - 02005976 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
2017-04-30 07:32 - 2017-01-06 15:42 - 00312744 _____ () C:\Program Files (x86)\Maxthon\bin\Maxzlib.dll
2017-04-30 07:32 - 2017-01-06 15:42 - 09266600 _____ () C:\Program Files (x86)\Maxthon\Core\Blink\plugins\pdf.dll
2017-04-30 07:32 - 2017-01-06 15:42 - 16393032 _____ () C:\Program Files (x86)\Maxthon\Core\Blink\plugins\pepflashplayer.dll
2017-04-30 07:32 - 2017-01-06 15:42 - 01342776 _____ () C:\Program Files (x86)\Maxthon\Core\Blink\libglesv2.dll
2017-04-30 07:32 - 2017-01-06 15:42 - 00219448 _____ () C:\Program Files (x86)\Maxthon\Core\Blink\libegl.dll
2017-04-30 07:32 - 2017-01-06 15:42 - 02354488 _____ () C:\Program Files (x86)\Maxthon\Core\Blink\ffmpegsumo.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-10 14:04 - 2017-05-31 07:09 - 00000864 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 activation.cloud.techsmith.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1594962750-1340225539-4068360994-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Kris\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{369b9964-a947-4865-b3e3-90185b3abe7f}.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{5580588F-102F-49B4-99EE-A5748927C880}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{B70C05C2-FA7D-479B-9C21-72642D776143}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{7F2A2A00-F78A-4569-8F09-BE6245548A1A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{D6EF5B11-2D82-417C-B454-C5F010F8FC68}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{AD86628B-7987-4B43-BE05-4FA3F402377A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{CE0F6530-4EFC-49BA-BB6A-F911D8D67130}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{D01F518A-C98E-495E-921C-CCDDFCF775BC}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{162520EA-96EF-4C0C-B37D-4A0D4A5B5F1C}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{5151D8DB-A5D6-402B-AEE7-78B8B00978D7}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{6B9AA5F0-2E21-4538-B6F0-B16F2EA5191A}] => (Allow) C:\Users\Kris\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{06EC6EDE-4685-4796-B6AD-8E1E9DCAB9EC}] => (Allow) C:\Users\Kris\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{985F61C0-C636-4C2F-85CD-41DB4D757621}] => (Allow) C:\Users\Kris\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C028404A-6ED6-4D21-AECC-EFEA12A2CF84}] => (Allow) C:\Users\Kris\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{FB442041-E126-4E41-A6F2-980FA44EC9D7}] => (Allow) C:\Users\Kris\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{9D12ACB4-738F-4B4F-B1EC-CE4137E678F3}] => (Allow) C:\Users\Kris\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{793C2E23-DB8A-4003-8825-EEE1C6223612}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [UDP Query User{5D3F42E5-4546-4BFE-BE80-6EFACDA33F47}C:\windows\kmsemulator.exe] => (Allow) C:\windows\kmsemulator.exe
FirewallRules: [{651261B1-54F5-4572-81AC-A8C118AF63C6}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{07FFEE86-2217-447A-8E11-89CD17F51C43}D:\games\grand theft auto v\gta5.exe] => (Allow) D:\games\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{CBFB03DC-F1A8-4EE0-A3F9-2BAACE2B5F34}D:\games\grand theft auto v\gta5.exe] => (Allow) D:\games\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{8C7238B8-AED2-4F9A-AC58-09F35C7B1918}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [UDP Query User{66CA23FB-CC45-4AFC-816F-A2285DEB93A3}C:\program files (x86)\arduino\java\bin\javaw.exe] => (Allow) C:\program files (x86)\arduino\java\bin\javaw.exe
FirewallRules: [TCP Query User{EA93A6BE-7B4A-4F80-819F-41598B1FEDDD}C:\users\kris\google drive\programs\packetsenderportable\packetsender.exe] => (Block) C:\users\kris\google drive\programs\packetsenderportable\packetsender.exe
FirewallRules: [UDP Query User{67E63ECB-EA75-4E0D-9C99-4DCE7218C704}C:\users\kris\google drive\programs\packetsenderportable\packetsender.exe] => (Block) C:\users\kris\google drive\programs\packetsenderportable\packetsender.exe
FirewallRules: [{3DF22F68-8B18-4EBD-BCEC-3620BAEC4812}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\devenv.exe
FirewallRules: [TCP Query User{9E8CDFEF-468F-4EFD-A78A-E6820834DCD8}C:\programdata\oracle\java\javapath_target_89831312\java.exe] => (Allow) C:\programdata\oracle\java\javapath_target_89831312\java.exe
FirewallRules: [UDP Query User{8316552B-F293-4D9B-9807-8FA1887B93A4}C:\programdata\oracle\java\javapath_target_89831312\java.exe] => (Allow) C:\programdata\oracle\java\javapath_target_89831312\java.exe
FirewallRules: [TCP Query User{1F29661C-A893-458D-BE9A-5A9B90C2D9A1}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{1BF483B7-22D7-49D8-8047-C6107CBA490A}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Block) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{902E73BC-F006-443D-8FF2-5B5089329A6D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{59AFD59C-A662-4B49-8149-0A7C3A482D66}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{90067536-C9D2-4BF8-AB82-80781C20B833}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{B7FA8940-529D-4AF0-9E90-5E58BF7F9582}] => (Allow) C:\Program Files\Opera\45.0.2552.881\opera.exe
FirewallRules: [{0351C083-B1D3-476B-93CC-E00652A0FD93}] => (Allow) C:\Program Files\Opera\45.0.2552.888\opera.exe
FirewallRules: [{F911DA7F-B078-4BDC-83EC-11344E6257E1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{D6EED670-786C-468A-8F29-D11F1A6FC2E7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{1E5A340D-264E-44FD-8C77-AA8DB924250D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{8C63878F-7E32-4103-AB82-5F6516425FF8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Faulty Device Manager Devices =============

Name: 690LC
Description: 690LC
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (06/12/2017 07:30:35 AM) (Source: IntelDalJhi) (EventID: 4) (User: )
Description: Intel(R) Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid.

Error: (06/12/2017 07:30:35 AM) (Source: IntelDalJhi) (EventID: 4) (User: )
Description: Intel(R) Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid.

Error: (06/12/2017 04:53:06 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\redist\1033\vcredist_arm.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (06/11/2017 12:14:08 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\redist\1033\vcredist_arm.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (06/10/2017 01:42:22 PM) (Source: IntelDalJhi) (EventID: 4) (User: )
Description: Intel(R) Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid.

Error: (06/10/2017 01:42:22 PM) (Source: IntelDalJhi) (EventID: 4) (User: )
Description: Intel(R) Dynamic Application Loader Host Interface Service initialization failure - the spooler applet is invalid.

Error: (06/10/2017 03:42:22 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\redist\1033\vcredist_arm.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (06/09/2017 04:29:43 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\redist\1033\vcredist_arm.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (06/08/2017 04:06:45 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\redist\1033\vcredist_arm.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (06/07/2017 03:32:10 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Visual Studio 11.0\VC\redist\1033\vcredist_arm.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,language="*",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (06/12/2017 02:31:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/12/2017 07:30:31 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/12/2017 04:46:01 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/12/2017 04:45:54 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The CG6Service service failed to start due to the following error: 
The system cannot find the file specified.

Error: (06/12/2017 04:45:53 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 4:44:30 AM on ‎6/‎12/‎2017 was unexpected.

Error: (06/12/2017 04:44:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The CG6Service service failed to start due to the following error: 
The system cannot find the file specified.

Error: (06/12/2017 04:44:30 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 3:15:11 AM on ‎6/‎12/‎2017 was unexpected.

Error: (06/11/2017 09:05:30 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/11/2017 09:00:40 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/11/2017 12:12:32 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


CodeIntegrity:
===================================
  Date: 2017-06-10 00:21:17.583
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-06-02 21:53:50.841
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-06-01 00:17:23.375
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-05-30 23:57:02.639
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-05-28 21:47:44.272
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-05-27 12:16:32.708
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.

  Date: 2017-05-27 12:16:17.836
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.

  Date: 2017-05-27 12:16:17.537
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.

  Date: 2017-05-15 10:13:52.277
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2017-05-11 07:22:19.364
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
Percentage of memory in use: 46%
Total physical RAM: 8131.13 MB
Available physical RAM: 4338.98 MB
Total Virtual: 9411.13 MB
Available Virtual: 4930.54 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:118.69 GB) (Free:69.17 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:578.84 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 119.2 GB) (Disk ID: D5F43134)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: F728F054)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Ще прегледам логовете!

Предполагам пишеш на Python и на C/C++

Също така предполагам, че този файл по-долу си го създал ти?

Цитат

2017-06-11 22:45 - 2017-06-11 22:56 - 01048205 _____ C:\Users\Kris\Desktop\Test.exe

?

  • Автор
преди 8 минути, Stoyannnov написа:

Ще прегледам логовете!

Предполагам пишеш на Python и на C/C++

Също така предполагам, че този файл по-долу си го създал ти?

?

Да, точно така.

Стъпка 1

Изтеглете TFC

  • Запазете файла на вашия десктоп.
  • Затворете всички отворени програми.
  • Стартирайте TFC.exe като администратор(Run As Administrator).
  • Изберете бутона START
  • След почистването системата ще се рестартира!

 

Стъпка 2

Изтеглете: MKLLMRQ.png Malwarebytes Anti-Malware.

  • Стартирайте инсталационния файл и следвайте съветника за инсталация.
  • Преди края на инсталацията премахнете отметката от: "Enable free trial of Malwarebytes Anti-Malware Premium" и се уверете че има отметка пред "Launch Malwarebytes Anti-Malware".
  • Отидете до табът Settings => Detection and Protection => сложете отметка на "Scan for rootkits".
  • Отидете до табът Dashboard => натиснете бутона "SCAN NOW".
  • Програмата автоматично ще провери за актуализации и ще започне сканирането.

Забележка: Ако видите съобщението "Could not load DDA driver" натиснете бутона "YES". След което разрешете на системата да се рестартира.

  • След като проверката приключи натиснете бутона "Remove Selected".
  • Системата ще поиска рестарт, съгласете се.
  • След като системата зареди MBAB ще зареди.
  • Отидете до табът History => Applications Logs.
  • Потърсете лог с име "SCAN LOG" с последната дата и час и натиснете върху него.
  • Натиснете бутона EXPORT => Copy to Clipboard.
  • Поставете съдържанието на лога с клавишната комбинация CTRL+V към следващия Ви коментар.

 

Стъпка 3

Изтеглете: QlYrtp7.jpg HitmanPro.

  • Запазете файла на вашия десктоп.
  • Стартирайте програмата.

Забележка: Програмата ще се актуализира, след актуализацията HitmanPro ще се рестартира.

  • Натиснете бутона "Напред".
  • Сложете отметка на лицензионното споразумение и натиснете отново бутона "Напред".
  • Кликнете върху "Не, искам да извърша еднократно сканиране на компютъра" и натиснете бутона "Напред".
  • Програмата ще започне да сканира. Сканирането ще отнеме ~2 минути.
  • След като сканирането приключи от списъка с намерените обекти(ако има такива) изберете Apply to all => Ignore.
  • Натиснете бутона "Next" и след това бутона "Изнеси резултатите от сканирането в XML файл" и запазете лог файла на десктопа.
  • Отворете лог файла, копирайте съдържанието му и го поставете в следващия Ви коментар.

Забележка: Ако от падащото меню няма Ignore тогава просто затворете програмата след края на проверката без да премахвате нищо!

От My Computer => Tools => Folder Options => View => Сложете отметка пред "Show hidden files, folders and drives".
Натиснете Apply.

Влезте в C:\Programdata\HitmanPro\Logs прикачете лога към следващия Ви коментар.

  • Автор

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 06/12/17
Scan Time: 20:24
Logfile: 
Administrator: Yes

Version: 2.2.1.1043
Malware Database: v2017.06.12.03
Rootkit Database: v2017.05.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 10
CPU: x64
File System: NTFS
User: Kris

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 330563
Time Elapsed: 8 min, 11 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
CrackTool.Agent.Keygen, C:\Windows\AutoKMS.exe, Quarantined, [7fd4231b8920fc3a91cc1a61db266e92], 

Physical Sectors: 0
(No malicious items detected)


(end)

HitmanPro 3.7.20.286
www.hitmanpro.com
	   Computer name . . . . : KRIS-PC
   Windows . . . . . . . : 10.0.0.14393.X64/4
   User name . . . . . . : KRIS-PC\Kris
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Trial (31 days left)
	   Scan date . . . . . . : 2017-06-12 20:36:01
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 1m 12s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : Yes
	   Threats . . . . . . . : 2
   Traces  . . . . . . . : 133
	   Objects scanned . . . : 2,083,597
   Files scanned . . . . : 38,164
   Remnants scanned  . . : 419,602 files / 1,625,831 keys
	Malware _____________________________________________________________________
	   C:\Program Files\KMSpico\AutoPico.exe -> Quarantined
      Size . . . . . . . : 745,664 bytes
      Age  . . . . . . . : 43.5 days (2017-04-30 07:24:43)
      Entropy  . . . . . : 6.3
      SHA-256  . . . . . : 4A714D98CE40F5F3577C306A66CB4A6B1FF3FD01047C7F4581F8558F0BCDF5FA
      Needs elevation  . : Yes
      Product  . . . . . : AutoPico
      Publisher  . . . . : @ByELDI
      Description  . . . : AutoPico
      Version  . . . . . : 16.1.0.0
      RSA Key Size . . . : 1024
      LanguageID . . . . : 0
      Authenticode . . . : Valid
    > Kaspersky  . . . . : not-a-virus:RiskTool.Win32.ProcPatcher.aat
      Fuzzy  . . . . . . : 93.0
      Startup
         C:\WINDOWS\system32\Tasks\AutoPico Daily Restart
      References
         C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico\AutoPico.lnk
	   C:\Program Files\KMSpico\Service_KMS.exe -> Quarantined
      Size . . . . . . . : 745,664 bytes
      Age  . . . . . . . : 43.5 days (2017-04-30 07:24:43)
      Entropy  . . . . . : 6.3
      SHA-256  . . . . . : 2B533757086499E224D5717F94A0F4C33E705398A7610219D82B9D3BC8763378
      Needs elevation  . : Yes
      Product  . . . . . : Service_KMS
      Publisher  . . . . : @ByELDI
      Description  . . . : Service_KMS
      Version  . . . . . : 17.1.0.0
      RSA Key Size . . . : 1024
      Service  . . . . . : Service KMSELDI
      LanguageID . . . . : 0
      Authenticode . . . : Valid
      Running processes  : 2720
    > Kaspersky  . . . . : not-a-virus:RiskTool.Win32.ProcPatcher.aat
      Fuzzy  . . . . . . : 90.0
      Startup
         HKLM\SYSTEM\CurrentControlSet\Services\Service KMSELDI\
	
Suspicious files ____________________________________________________________
	   C:\Users\Kris\Desktop\FRST64.exe
      Size . . . . . . . : 2,438,656 bytes
      Age  . . . . . . . : 0.1 days (2017-06-12 18:28:50)
      Entropy  . . . . . : 7.6
      SHA-256  . . . . . : 2C720E506BC7C371F5DB5A885843656D9DCEAD3FDB59DF15FECC1B6B307964FB
      Needs elevation  . : Yes
      Fuzzy  . . . . . . : 24.0
         Program has no publisher information but prompts the user for permission elevation.
         Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
         Authors name is missing in version info. This is not common to most programs.
         Version control is missing. This file is probably created by an individual. This is not typical for most programs.
         Time indicates that the file appeared recently on this computer.
      Forensic Cluster
         -30.0s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\4\80\51545FB9C04E9BDC.dat
         -29.5s C:\Windows\Logs\WindowsUpdate\WindowsUpdate.20170612.182821.327.1.etl
         -28.6s C:\Windows\Prefetch\NVTRAY.EXE-981FA625.pf
         -28.4s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{3259E743-B187-481C-A92F-2BD0D0D476C7}
         -23.8s C:\Windows\Prefetch\DLLHOST.EXE-829F390C.pf
         -18.8s C:\Windows\Prefetch\FRST64.EXE-17FA586D.pf
         -16.5s C:\FRST\
         -16.5s C:\FRST\Hives\
         -16.5s C:\FRST\Logs\
         -16.5s C:\FRST\Quarantine\
         -16.0s C:\ProgramData\Microsoft\Windows Defender\Scans\RtSigs\Data\4bae83b291d93ae2fbc74fb6edd5f7a6ec36e545
         -15.8s C:\FRST\Hives\ERDNT.INF
         -15.8s C:\FRST\Hives\ERDNT.CON
         -15.8s C:\FRST\Hives\SYSTEM
         -15.6s C:\FRST\Hives\SOFTWARE
         -15.5s C:\Windows\Prefetch\ERUNT.EXE-399FC5BA.pf
         -14.8s C:\FRST\Hives\SAM
         -14.8s C:\FRST\Hives\SECURITY
         -14.8s C:\FRST\Hives\DEFAULT
         -14.8s C:\FRST\Hives\Users\
         -14.8s C:\FRST\Hives\Users\00000001\
         -14.8s C:\FRST\Hives\Users\00000001\NTUSER.DAT
         -14.7s C:\FRST\Hives\Users\00000002\
         -14.7s C:\FRST\Hives\Users\00000002\UsrClass.dat
         -14.7s C:\FRST\Hives\BCD
         -14.7s C:\FRST\Hives\DRIVERS
         -14.6s C:\FRST\Hives\ERDNT.EXE
         -14.6s C:\FRST\Hives\ERDNTWIN.LOC
         -14.6s C:\FRST\Hives\ERDNTDOS.LOC
         -14.5s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\80\51545FB9C04E9BDC.dat
         -14.3s C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\VYWTQP3E.cookie
          0.0s C:\Users\Kris\Desktop\FRST64.exe
          0.0s C:\Users\Kris\AppData\Roaming\Maxthon3\Public\Downloader\TaskList\{B9695899-509F-4C99-AF48-7D7231FBFEC7}.tsk
          3.9s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\08\
          3.9s C:\ProgramData\Microsoft\Windows Defender\Scans\MetaStore\2\08\FA9CF09169B7D4AC.dat
          6.0s C:\Windows\Prefetch\DLLHOST.EXE-6A829A47.pf
          8.2s C:\Users\Kris\Desktop\FRST.txt
          9.1s C:\ProgramData\Microsoft\Windows Defender\Scans\RtSigs\Data\0fac8e6ba435579f263b6728e2a091184b79e0f6
          9.6s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{0CAC301B-E49B-4661-A783-47861936622E}
         24.9s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{C201089C-300D-4B95-B261-2F21B92C537D}
         47.3s C:\Windows\Prefetch\BCDEDIT.EXE-EB47CDA5.pf
         47.7s C:\Users\Kris\Desktop\Addition.txt
         49.2s C:\ProgramData\Microsoft\Windows Defender\Scans\RtSigs\Data\8aecb997a01b0442331ee93517f1f2b46da4a1cb
         53.3s C:\Windows\Prefetch\MOD_FRST.EXE-0104096A.pf
         55.4s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{D8DA283E-2893-4D6B-A7D1-F6825C4B7A77}
         62.7s C:\Windows\Prefetch\WEVTUTIL.EXE-4CD23CAE.pf
         63.3s C:\FRST\Logs\Addition_12-06-2017 18.29.54.txt
         63.3s C:\FRST\Logs\FRST_12-06-2017 18.29.54.txt
         66.1s C:\Windows\Prefetch\DLLHOST.EXE-BF26B840.pf
         70.7s C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{80F67012-ED55-4613-8753-53A80596B8A6}
         71.2s C:\Windows\Prefetch\VSSVC.EXE-206E55B3.pf
         71.2s C:\Windows\Prefetch\SVCHOST.EXE-38BE90DD.pf
	
Cookies _____________________________________________________________________
	   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:adaptv.advertising.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:addthis.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:adnxs.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.linkedin.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.servebom.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:adsrvr.org
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:agkn.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:angsrvr.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidr.io
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:bidswitch.net
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:bluekai.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:contextweb.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:crwdcntrl.net
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:ctnsnet.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:d.adroll.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:default.atemda.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:demdex.net
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:domdex.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:dpm.demdex.net
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:dsp.linksynergy.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:everesttech.net
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:imrworldwide.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:linksynergy.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:match.adsby.bidtheatre.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:mathtag.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:mookie1.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:nexac.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:openx.net
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:pixel.rubiconproject.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:pubmatic.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:rfihub.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:rlcdn.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:rubiconproject.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:scorecardresearch.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:tap2-cdn.rubiconproject.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:tapad.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:turn.com
   C:\Users\Kris\AppData\Local\Google\Chrome\User Data\Default\Cookies:xiti.com
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\0A5PY5AE.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\0BSWV873.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\27FGCFVY.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\3HS2XS30.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\5GXDXPDI.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\7GFV4PNI.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\7NI69F02.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\7Z65NF1R.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\BCY5DQMJ.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\GZSTC4J0.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\K1CCD7I3.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\1U0XYTKK.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\221UF7B0.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\2YJVPDTI.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\35QEALVI.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\3XHXPEJ6.txt
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\4ES3RAOW.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\4GV03GR4.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\61CABT2X.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\6JJX5RHV.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\8SEB7XHT.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\9B09TD6S.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\9DVQN780.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\AD7WETRP.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\AHJ6EM09.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\BKNK2Y8A.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\CIF2AM5J.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\CPXI80TJ.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\DEJ11AUE.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\E56H1O8G.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\EEUTV8JF.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\EHFZ5TRO.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\EQ9QFYY3.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\GA0RI6TF.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\GCD80VQ5.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\I44XE6OH.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\IMJUCC60.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\JDQM4V22.txt
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\JULTBCYI.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\JWRCVP4Q.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\KAXMGDIT.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\LDJV4I2C.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\M63ECUMU.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\NO446FJ1.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\NZYLNWT1.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\PBN86B3C.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\PJ51X1GZ.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\Q3CFA4SH.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\Q9EJI6W8.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\R1PLLU0F.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\RICQ5U12.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\S3U16GHW.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\VMBU3T3M.txt
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\Low\XLF1Q6QS.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\M23ZPMUN.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\O4LVHESD.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\PXCJMLU7.cookie
   C:\Users\Kris\AppData\Local\Microsoft\Windows\INetCookies\XUVAUC8X.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\0PGHNKDG.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\3P7DCIOV.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\8BFNAXDR.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\8JFHY1TF.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\9N6450M6.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\C76P39AD.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\CYYLR647.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\D1521Y9A.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\FSSS6B7S.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\GOUSN81L.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\GSJK1NST.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\JIV8XADC.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\M40XUGUL.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\OU0YEAJS.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\U2CUQ3FU.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\YLHIDDGK.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\ZJIPGWU0.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!001\MicrosoftEdge\Cookies\ZUJ9LYMN.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\Cookies\DAM2X0S4.cookie
   C:\Users\Kris\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\#!002\MicrosoftEdge\Cookies\ED6USVSA.cookie
   C:\Users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\ei5xjl3l.default\cookies.sqlite:adform.net
   C:\Users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\ei5xjl3l.default\cookies.sqlite:demdex.net
   C:\Users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\ei5xjl3l.default\cookies.sqlite:dpm.demdex.net
   C:\Users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\ei5xjl3l.default\cookies.sqlite:everesttech.net
   C:\Users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\ei5xjl3l.default\cookies.sqlite:rlcdn.com
   C:\Users\Kris\AppData\Roaming\Mozilla\Firefox\Profiles\ei5xjl3l.default\cookies.sqlite:track.adform.net


 

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.